Start-Up Applications - All

Last update :- 29th April, 2008
16820 items listed

Introduction

This page presents a searchable, comprehensive list of the programs you may find that run when you switch on your PC as typically identified by MSCONFIG or the registry "Run" keys - and whether you need them.

Close Program/Task Manager

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Operating System Differences

A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Noeton eMail Protect" in the registry.

To avoid the list becoming too large, all VIRUSES are shown using the registry version which is common to all Windows versions.

Random startup entry/filename viruses

There are viruses and other pests that can add any number of different entries to the startups. They make additional entries under the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\ Run and RunOnce keys, allowing them to run at startup. In all cases below, %system% is a variable - by default this is C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP):

  1. PE_BISTRO - adds "XXXX"="C:\WINDOWS\XXXX.EXE" - where XXXX is the randomly chosen filename of the dropped file
  2. MAGISTR.A - adds "[Virus file name]"="[Virus Path and file name].EXE"
  3. BUGBEAR.A or BUGBEAR.C or BUGBEAR.E - adds ""=%System%\"[random filename].EXE"
  4. OPTIXPRO.11 - adds "%Registry entry%"="%Path%\%Filename%"
  5. Lop.com homepage hijacker - adds multiple and random startup entries
  6. FreeScratchAndWin - adds multiple and random startup entries as it includes LOP above
  7. nCase (or n-Case) parasite - adds multiple and random startup entries
  8. LORAC - adds "[four random characters]"="%Sysdir%\abcdef.exe"
  9. MOSUCK - random name and filename in C:\Windows or C:\Winnt
  10. DEBORMS.D - adds one of a number of valid Name/Startup Item entries but points to the path of the worm file dropped
  11. GIBE.C - adds random name and filename in C:\Windows or C:\Winnt
  12. SWEN.A - adds random name and filename
  13. ZOMBAM.B - adds random name and filename
  14. WANADO or REUR - adds "XXXXXXXX"="%Sysdir%\XXXXXXXX.exe" where X can be any random hexadecimal (0-9, A-F) number
  15. SINCOM - adds random name and filename in C:\Windows or C:\Winnt with "Run:Auto" appended to the command/data column entry
  16. SOBER family - adds "[random string]"="%system%\[random filename.exe]"
  17. BRANCOS.C - adds "win_[4 random characters][4 random numbers 0-9]"="%System%\SYS_386X\[4 random characters][4 random numbers 0-9].exe"
  18. IRC.BOT.B - adds random name and filename
  19. COREFLOO-C - adds "[random filename]"="rundll32 %SYSTEM% [random filename].dll,Init 1"
  20. [random digits].exe = [random digits].exe - 8 random digits, example: 77231997.exe = 77231997.exe. Winpup.exe adult content downloader
  21. DRAGONQQ - "[Trojan's filename]"="[Path to the Trojan]", "[Random name]"="C:\WINNT\[Random name].exe", "[Random name]"="C:\Program Files\[Random name].exe" or "[Random name]"="C:\WINDOWS\[Random name].exe"
  22. FORMADOR - adds "[executed file name]"="%System%\[executed file name].exe"
  23. NETTRASH - adds "[file name]"="[path to filename].exe"
  24. OPTIXPRO.13B - adds "[registry value name]"="[path to trojan].exe"
  25. MYDOOM.F or MYDOOM.G or MYDOOM.H - adds "[4 to 8 random, lowercase letters]"="[worm filename]"
  26. ANNIL - adds random name and filename
  27. ANTINNY.G and ANTINNY.K - adds "[random name]"="[path to worm]"
  28. KILLAV.D - adds "[Trojan filename]"="%Windir%\[Trojan file name]" where %Windir% is C:\Windows or C:\Winnt
  29. MYPOO - adds "[value name]"="[Trojan file name]" where [value name] is configurable
  30. BLACKMAL or BLACKMAL.B - adds "[random_file_name1].exe"="%System%\[random_file_name1].exe"
  31. ERKEX.A - adds "[random_file_name]"="%System%\[random_file_name].exe"
  32. OPASA - adds "[random_file_name]"="%System%\[random_file_name].exe"
  33. GAOBOT.ADN - adds random name and filename
  34. ADWAHECK - adds "[trojan name]"="%System%\[trojan filename]"
  35. GOBOT.A - adds random name and filename in C:\Windows or C:\Winnt
  36. Sandboxer adware - adds random name and filename
  37. AGENT.B - adds "[1-5 random characters]"="RUNDLL32 %System%\[DLL filename].dll,StreamingDeviceSetup"
  38. EXRUNTEL - adds "[original filename]"="%System%\[original filename]"
  39. Margoc adware - adds random name and filename
  40. Winpup adware - adds random name and filename in %System%
  41. KETCH - adds "[word]"="%System%\[word][number].exe"
  42. DARBY.B - adds "[random worm filename]"="%System%\[random worm filename]"
  43. VUNDO - adds "*[trojan name]"="[trojan path]"
  44. BEAKER.A - adds "[5 random lower-case char]"="[5 random lower-case char].exe" in the System, system32, Temp and Fonts sub-directories of %Windir%
  45. LIFEFORENOW - adds "[random filename]"="%System%\[random filename].exe"
  46. DIMI - adds "[random value name]"="%System%\[random filename].exe"
  47. ABEBOT - adds "[random service name]"="[random filename].exe -services"
  48. OMEGA - adds "[random value]" = "%Windir%\[random file name].exe"
  49. NAMSHARE - adds "[Random service name]" = "[Random file name]"
  50. REANET.B - adds "[file name]" = "[path to file name]"
  51. BANCOS.Q - adds "[filename prefix]" = "[path to filename]"
  52. SPYBOTER.GEN - adds "[key name]" = "[file name of Trojan]"
  53. BOTUK - adds "[random characters]Srv32" = "[random characters]srv.exe"
  54. MADTOL-A - adds "[trojan filename]" = "%System%\[trojan filename]"
  55. HESIVE - adds "[trojan filename]" = "[path to trojan]"
  56. Spyware/Adware/Malware/Foistware & Hijackers

    Check CastleCops for information about these types of program. They have very active forums. You may also want to try SpywareInfo for their forums and a list of startup program managers

    o-----------------------------o

    Search Query Courtesy of Dynamic Drive
    Press Alt+S if an entry is found to continue searching

    This search works with IE4+, NS4 and Mozilla/NS7+ but not NS6. Alternatively use your browsers search facility - Ctrl+F for IE users.

    Key:


      Name/Startup Item Command Comments
    Xsystem32.exeAdded by the AGOBOT-KU WORM! Note - has a blank entry under the Startup Item/Name field
    Xpathex.exeAdded by the MKMOOSE-A WORM! Note - has a blank entry under the Startup Item/Name field
    Xsvchost.exeAdded by the DELF-UX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field
    XMSPF.EXEAdded by a variant of the SDBOT WORM! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field
    Xdllvirtual.exeAdded by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field
    Xdllvirtual.dllAdded by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field
    Xdllvirtual.jsAdded by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field
    Xajsha5.exeAdded by the SPYBOT-NX WORM! Note - has a blank entry under the Startup Item/Name field
    Xne.exeAdded by the IRCBOT-ZL TROJAN!
    X SystemBootservices.exeAdded by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a HelpHelp subfolder of the Windows or Winnt folder
    X WinCheckservices.exeAdded by the SOBER-S WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "ConnectionStatusMicrosoft" subfolder of the Windows or Winnt folder
    X Windowsservices.exeAdded by the SOBER.X WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "WinSecurity" subfolder of the Windows or Winnt folder
    X WinStartservices.exeAdded by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a Connection WizardStatus subfolder of the Windows or Winnt folder
    X winsystem.syssmss.exeAdded by the SOBER.K TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a msagentwin32 subfolder of the Winnt or Windows folder
    Y!1_pgaccountpgaccount.exeDiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks. You will see one instant of pgaccount.exe for every active account on your system, and this is essential for PG to work properly
    Y!1_ProcessGuard_Startupprocguard.exeDiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks
    U!AVG Anti-Spywareavgas.exePart of AVG Anti-Spyware from Grisoft
    U!ewidoewido.exePart of Ewido anti-spyware
    N!NoLoadwinrecon.exeWinRecon keystroke logger/monitoring program - remove unless you installed it yourself!
    ?$EnterNetEnternet.exeConnection manager for the EnterNet ISP. You can also use RASPPOE
    X$sys$cmp$sys$xp.exeAdded by the RYKNOS.B TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer
    X$sys$crash$sys$sonyTimer.exeAdded by the WELOMOCH TROJAN!
    X$sys$crash$sys$sos$sys$.exeAdded by the WELOMOCH TROJAN!
    X$sys$crash$sys$WeLoveMcCOL.exeAdded by the WELOMOCH TROJAN!
    X$sys$drv$sys$drv.exeAdded by the RYKNOS TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer
    X$sys$momomomochin$sys$sonyTimer.exeAdded by the WELOMOCH TROJAN!
    X$sys$momomomochin$sys$sos$sys$.exeAdded by the WELOMOCH TROJAN!
    X$sys$momomomochin$sys$WeLoveMcCOL.exeAdded by the WELOMOCH TROJAN!
    X$sys$umaiyo$sys$sonyTimer.exeAdded by the WELOMOCH TROJAN!
    X$sys$umaiyo$sys$sos$sys$.exeAdded by the WELOMOCH TROJAN!
    X$sys$umaiyo$sys$WeLoveMcCOL.exeAdded by the WELOMOCH TROJAN!
    U$Volumouse$volumouse.exeVolumouse from Nirsoft. "Provides you a quick and easy way to control the sound volume on your system - simply by rolling the wheel of your wheel mouse"
    X$WindowsRegKey%updateIEXPLORE.EXEAdded by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    N%cmpmixtitle%%cmpmixstr%Possibly related to C-Media Mixer Control panel?
    N%FP%012-L2TP fts.exefts.exe012.Net.il Israeli ISP software front-end
    U%FP%012-L2TP FWPortal.exeFWPortal.exe012.Net.il Israeli ISP dial-up software
    N%FP%1776 Internet fts.exefts.exe1776 Internet US ISP software ISP software front-end
    U%FP%1776 Internet FWPortal.exeFWPortal.exe1776 Internet US ISP dial-up software
    N%FP%AIRTEL fts.exefts.exeBharti Airtel Broadband - Indian ISP software front-end
    N%FP%Barak013 fts.exefts.exeBarak013 Israeli ISP software front-end
    U%FP%Barak013 FWPortal.exeFWPortal.exeBarak013 Israeli ISP dial-up software
    N%FP%Friendly fts.exefts.exeFriendly ISP software front-end
    X(*)API MachinewinSOCKS.exeHomepage hijacker, see here (* = any digit)
    X(*)Runwin32API.exeHomepage hijacker, see here (* = any digit)
    X(default)[random filename].exeAdded by the BLACKMAL WORM! Note - this malware actually changes the default value data of the registry "Run" key in order to force Windows to launch it at boot. Name field may be empty
    X(default)rundll32.exe [path to DLL file], Do98WorkAdded by the HESIVE.B TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
    X(Default)5640.exeAdded by the DOWNLD-ABF TROJAN!
    X(L4r1$$4) (4nt1) (V1ruz)SP00Lsv32.pifAdded by the ASSIRAL.B WORM!
    X*Bandookmsdll.exeAdded by an unidentified TROJAN - see here
    X*JanisRuckenbrodIIjanis.comAdded by the POPS WORM!
    X*Microsoft Updatectxma.exeAdded by the STMU TROJAN!
    X*Microsoft Updatecxma.exeAdded by the STMU TROJAN!
    X*Microsoft Updatewstcl.exeAdded by the STMU TROJAN!
    X*Microsoft Updatewucxt.exeAdded by the STMU TROJAN!
    X*Microsoft Updatewuytc.exeAdded by the STMU TROJAN!
    X*MS Setup[random filename]Virtumondo adware, also known as the VUNDO TROJAN!
    X*MSConfig32aecache.exeDetected by F-secure as the OBFUSCATED.GP TROJAN!
    X*Security Centersecctr.exeAdded by the SDBOT.BRO WORM!
    Y*StateMgrstatemgr.exeWindows ME default for System Restore. Do NOT disable!
    X*windows updatewrauclt.exeAdded by the RBOT-QU WORM!
    X*windows updatewuanclt.exeAdded by the RBOT-PG WORM!
    X*windows updatewuaucrlt.exeAdded by the SPYBOT.HUR WORM!
    X*windows updatewuraclt.exeAdded by the RBOT-PO WORM!
    X*windows updatewurauclt.exeAdded by the RBOT-SY WORM!
    X*windows updatewsctl.exeAdded by the SPYBOT.PR WORM!
    X*windows updatewkmst.exeAdded by the SDBOT.AVD WORM!
    X*windows updatewscxt.exeAdded by the RBOT.AOS WORM!
    X*windows updatewaurclt.exeAdded by a variant of the RBOT WORM!
    X*Windows [filename] Checker[filename]Added by the KEDEBE-B WORM!
    X*WindowsAudiosystemupd.exeAdded by the AGENT-TH WORM!
    X*WinLogon[trojan path] ren time:[random number]Added by the VUNDO TROJAN!
    X*winstatswinstats.exeAdded by the GARGAFX TROJAN!
    X*wuauclt.exew****.exe [* = random char]Added by a variant of the RBOT-UG WORM! Note - * in the filename represents a random char; variants spotted: wxmct.exe, wtmsv.exe, wxmst.exe, wmsvc.exe and so on...
    X,main drive Loaderwininfo.exeSuspected malware as it appears in 3 different registry locations - see here
    X-=+(L4r1$$4)+=-(4nt1)-=+(V1ru$)=-+ISASS.exeAdded by the ASSIRAL.B WORM!
    Y-FreedomNeedsRebootZkRunOnceR.exeInternet Security Suite used by ISPs to protect customers against many attacks
    X..ABC2007.exeAdded by the DLOADR-ASH TROJAN!
    X.mscdrlassa.exeAdded by the WEBUS.C TROJAN!
    X.mscdrlsvchost.exeAdded by the WEBUS.D TROJAN!
    X.mscdsrlsvchost.exeAdded by the CR TROJAN!
    X.mscsblsvhost.exeAdded by the CMQ TROJAN!
    X.msfupdatemsveup.exeAdded by the ALLOCUP.A WORM!
    X.mssecuremssecure.exeAdded by the DDOS_BOXED.X TROJAN!
    ?.NET configsysmon32.exe??
    X.NET.msnmgnr.exeAdded by the DELF.AYF WORM!
    X.nortonrchost.exeAdded by the BOXED-H TROJAN!
    X.nvsvcsmss.exeAdded by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!
    X.nvsvcbsmssb.exeAdded by the BOXED.CG TROJAN!
    X.Progservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
    X.Progwinlogon.exeAdded by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
    X.protectedN/ASmitfraud variant
    X.svchostCSRSS.EXEAdded by the WEBUS.F TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder
    X.TEXTCONVcsrss.exeAdded by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
    X.TEXTCONVlsass.exeAdded by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder
    X.WMAudiocsrss.exeAdded by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
    X.WMAudiolsass.exeAdded by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder
    N/l:engN/ARelated to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file, but it's easily available using the search function
    U000pit.exePrivateEye surveillance software. Uninstall this software unless you put it there yourself
    X000hpdllhoshpdllhost.exeLZIO.com adware downloader
    U000StTHK000StTHK.exeToshiba Hot key functionality for the function keys (Fn-Esc, Fn-F1 (lock), Fn-F2, Fn-F3, Fn-F4, Fn-F5 (switching between laptop and CRT display output), etc...)
    X0050726-007-i32-10050726-007-i32-1.exeAdded by the BANCBAN-EC TROJAN!
    ?00DSKSVR00desksaver.exeRelated to Advanced Desktop Shield
    ?00DSKSVR01desksaver.exeRelated to Advanced Desktop Shield
    Y00PCTFWFirewallGUI.exePC Tools Firewall Plus - "powerful free personal firewall for Windows that protects your computer by preventing unauthorized users from gaining access to your computer through the Internet or a network"
    Y00TCrdMainTCrdMain.exeRelated to the flash card slot on a Toshiba laptop. Ending this process will disable access to the flash cards
    U00THotkey00THotKey.exeFor Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev.
    U00THotkeysystem32THotkey.exeFor Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev
    U0190 WarnerWARN0190.EXEAnti-dialer program (Germany)
    U0900 WarnerWARN0900.EXEAnti-dialer program (Germany)
    X0mcamcap0mcamcap.exeAdded by the COSIAM-H TROJAN!
    X0utlook Express*****.exe [* = random char]Added by the RBOT-CC WORM! Note the first letter is actually the digit "0" and not a capital "o"
    X11.exeAdded by the ESTEEMS TROJAN!
    X1lsass.scrAdded by the BANCOS.V TROJAN!
    X1svchost.scrAdded by the BANCOS.X TROJAN!
    N1&1 EasyLoginEasyLogin.exe1&1 EasyLogin - quick access to webhost 1&1's Control Panel, Web-Mail and other applications via the System Tray
    X1029BB4B-16A9-4E77-AA3D-96930BD68EECsysockeu.exeDetected by McAfee as the FAKEALERT-AH TROJAN! See here
    X1111swapmgr.exe1111swapmgr.exeAdded by the IC TROJAN!
    X123456rundll32.exe shell32.dll, Control_RunDLL ...123456.cplAdded by the KITRO.C (or DANDI.A) WORM! 123456 can be any random 3 to 6 digit number
    U12Ghosts Backup12backup.exe12Ghosts Backup - "Automatic Backups, HyperBackup for Multiple Versions, Registry Backup"
    U12Ghosts Clip12clip.exe12Ghosts Clip - "Screen shots made easy"
    U12Ghosts JustAWindow12window.exe12Ghosts JustAWindow - "Cover annoying ads, animated gifs, things you don't want to see"
    U12Ghosts Popup-Killer12popup.exe12Ghosts Popup-Killer
    U12Ghosts SaveLayout12autosl.exe12Ghosts SaveLayout - "Always (always!) keep the layout of your desktop icons"
    U12Ghosts SetColor12color.exe12Ghosts SetColor - "Change your desktop icon text colors, also to transparent"
    U12Ghosts ShowTime12showtime.exe12Ghosts Showtime - "Enhance the clock in your tray with font formatting, colors, date, time zones"
    U12Ghosts Synchronize12sync.exe12Ghosts Synchronize - "Sync PC clock with an atomic clock over the Internet"
    U12Ghosts Tower12tower.exe12Ghosts Tower - "Quickly access and manage all Ghosts (included in all packages)"
    U12Ghosts TrayProtect12srvc.exe12Ghosts TrayProtect - "Hide tray icons, restore after a crash"
    U12Ghosts Wash12wash.exe12Ghosts Wash - "Protect your privacy, clear browser history, delete and overwrite cache files"
    ?17779Proj2002N/A??
    X180adsolution180adsolution.exeNCase adware
    X180ax180ax.exeNCase adware
    X180ClientStubInstallstubinstaller****.exe [* = digit]180Solutions adware related
    X180ClientStubInstall[path to trojan]180Solutions adware related
    X180ClientStubInstall******.tmp [* = random digit/char]180Solutions adware related
    X1916435341.exe1916435341.exeAdded by the DLOADR-AXU TROJAN!
    X196_150_ni196_150_ni.exeWinFixer web installer. Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here
    X197_150_ni_3197_150_ni_3.exeWinFixer web installer. Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here
    N1:hpdrv.exeHP utility for monitoring when and how many recoveries have been done
    N1A:MacVisionTrayMonitorTrayMonitor.exeComes with the MacVision program for monitoring tray icons (Note : program is by Stardock)
    Y1A:Stardock MCPmcpserver.exeMaster Control Program for Stardock apps, in development. People should leave it running if they're using any of the Stardock applications
    Y1A:Stardock TrayMonitorTrayServer.exeFor monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX
    ?1CmailSNETMAIL.EXE??
    X1on11on1.exeAdult content dialler
    U1Srv32SpyAgent4.exeSpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC."
    X1u71u7.exeAdded by the MURBAC-A TROJAN!
    U1Win32CfgSpyBuddy.exeSpyBuddy keystroke logger/monitoring program - remove unless you installed it yourself!
    U1Win32CfgKeyloggerpro.exeKeyloggerpro keystroke logger/monitoring program - remove unless you installed it yourself!
    X1WinCfg32WebMailSpy.exeWebMailSpy spyware
    X2020Downloadermssvr.exe2020Search Toolbar
    X2177F056-0AA6-4D6C-A944-13F71F341C29sysokuaw.exeDetected by McAfee as the FAKEALERT-AH TROJAN! See here
    U24Online ClientCyberoamClient.exeRelated to Cyberroam from Elitecore Technologies Ltd
    X252winmgr.exeAdded by the LEGMIR-AT TROJAN!
    X27slsorve.exeAdded by the SLSORVE-A TROJAN!
    X27csrss32.exeAdded by the SLSORVE-D TROJAN!
    X27msm32.exeAdded by the SLSORVE-E TROJAN!
    X2Searchmain.exe2Search adware
    X2thousandbuck[path to file]Added by the RANKY.L TROJAN!
    U2wSysTray2portalmon.exe2Wire Homeportal user interface
    X32-bit Thunking servicethunk32.exeAdded by the DERDERO.A WORM!
    X333svchost.exeAdded by the JD-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This one is located in a "Syswm1i" directory
    X388529725448AutomaticUpdates.exeAdded by the SDBOT-DEN WORM!
    ?39ELTFH25Z8SKFEzg1q5.exeSeems to be associated with software by Resplendence SP ?
    Y3c1807pd3cmlink.exe 3cpipe-3c1807pd3Com WinModem driver. See here for more WinModem information
    Y3capplnk3capplnk.exeUS Robotics Modem driver
    N3cdminic3CDMINIC.EXE3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards
    Y3CM Link3cmcnkw.exeRequired for a US Robotics WinModem as it provides the link to Windows - won't work without it
    Y3Cmlink3CmlinkW.exeFor a US Robotics WinModem. Provides the link to Windows as the CPU does the processing on WinModems - won't work without it. See here for more WinModem information
    N3ComDMIAgent3CDMINIC.EXE3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards
    Y3cpipe-USRpdAUSRmlnkA.exeModem driver files from US Robotics
    X3D Text3D Text.scrAdded by the JERMY.A WORM!
    U3Deep Control Panel3DeepCTL.EXENow superseeded by ColorWizzard - 3Deep corrected lighting, shading and color for all your 2D and 3D games
    X3Dfx AccGFXACC.EXEAdded by the GIBE WORM!
    N3dfx Task Manager3dfxMan.exeSystem Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs
    Y3dfx Tools3dfxCmn.dllUpdates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards
    Y3dfxv2ps.dll3dfxv2ps.dllUpdates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards
    ?3Dlabs Taskbar Display Manager3DLman.exe3DLabs graphics driver related. System Tray access to display settings?
    U3DLabsHelperDemon3dldemon.exeDirectly from the programs author "It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore), so it should take zero CPU time and virtually zero memory, since it will all be paged out to the hard drive." In most cases it can be safely disabled
    Y3DMouse.EXE3DMouse.EXEDritek System Inc. 3D Mouse driver
    X3d_sound3d_sound.exeAdded by the RIADOS-A TROJAN!
    U3qdctl.exe3qdctl.exeProvided with Terratec 128i PCI and similar sound cards. Loads a sound profile at bootup, restoring volume and other audio settings to a pre-determined default. Similar to Creative Lab's AudioHQ
    Y3ware 3DM3dm.exeMonitors status of the disk array on 3ware IDE RAID controllers
    X456655explorer.exeAdded by the BIFROSE-DE TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System folder
    X4684735485910netdll32.exeAdded by the SDBOT-DEV WORM!
    X4da92ad5.exe4da92ad5.exeAdded by the DLOADR-WZ TROJAN!
    U4oDKHost.exeVerisign Kontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops
    X4wd!!!Natal!.pifAdded by the OPASERV.AI WORM!
    X5-1-61-96members-area.exeAdult content dialler
    X5-2-46-1125-2-46-112.exeAdult content pop-up dialler. Removal instructions here
    X55278grepclient1.exeAdded by the LINEAGE-S TROJAN!
    X5p4m[path to trojan]Added by the LITEBOT-C TROJAN!
    X5whgue215whgue21.exeClearSearch adware
    X666Ska.exeAdded by the PIPES TROJAN!
    X678lsas32.exeAdded by the SLSORVE-B TROJAN!
    X756349DC-6D9E-4F2A-9B24-269661F073C3sysoghcx.exeDetected by McAfee as the FAKEALERT-AH TROJAN! See here
    X7f8ez****.exe 9idfDetected by NOD32 as the SMALL.ALI TROJAN! Note - it creates a number of extra z****.dll files in the system32 folder
    U802.11b+g USB Wireless LAN UtilityZDWlan.exe802.11b+g USB Wireless LAN Utility
    U802.11g Wireless AdatperMonitor.exeRelated to wireless card (802.11) adapter/standard. System Tray icon that provides a shortcut to "Wireless Connection Status" and allows to turn WL on and off. Supplier unknown. Adapter is miss-spelled
    X852EBF20-A95D-4F1F-B9C2-B2CD24350F3Esysodkcs.exeDetected by McAfee as the FAKEALERT-AH TROJAN! See here
    X98D0CE0C16B1rundll32.exe D0CE0C16B1, D0CE0C16B1BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
    X9mwinlog0n.exeAdded by the LEGMIR-AQK TROJAN!
    Y9xadiras9xadiras.exeAllied Telesyn AT series router/modem related - apparently required
    X9xHtProtectAVprotect9x.exeAdded by the NETSKY.M WORM!
    X;Rundll[filename]Added by the PWSLEGMIR.E TROJAN!
    X?ekio Startups?nksvc32.exeAdded by the AGOBOT-OV WORM where ? is a random character
    U?Torrentutorrent.exe?Torrent - BitTorrent client for Windows sporting a very small footprint. It was designed to use as little cpu, memory and space as possible while offering all the functionality expected from advanced clients
    X@regedit -s ..win.dllAdded by the SEEKER.K TROJAN!
    N@Hoc ToolbarAtHoc.exeOne-click activated browsing toolbar used by various web-sites. See here for more info
    N@lohareminder.exeRegistration reminder for @loha@home E-mail utility
    X@tour_ww@tour_ww[1].exeAdult content dialler
    Xaa.exeCommercials file that registers itself in the system registry and redirects IE to a certain commercial website
    Xajesse.exeAdded by the MELO-A WORM!
    XA New Windows Updaterw32NTupdt.exeAdded by the MYTOB.BM WORM!
    NA NoteA Note.exe"A Note is a program that lets you create post-it like notes on your Microsoft Windows desktop"
    UA Verizon AppVERIZO~1.EXEPart of Verizon Online Support Manager
    Ua-squareda2guard.exea-Squared antitrojan - can be run on demand but necessary in Startup if you prefer the a? 'Background Guard' real time protection feature
    Ya-squared Anti-Dialera2adguard.exea-sqaured Anti-Dialer
    Ya-winpoet-servicewinpppoverethernet.exeWinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking
    UA1000 Settings Utilitycpqa1000.exeCompaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan, print, copy and fax. Only required if you use these features
    UA4ProxyA4Proxy.exeAnonymity 4 Proxy - local proxy server that makes you anonymous when visiting web sites
    XA70F6A1D-0195-42a2-934C-D8AC0F7C08EBrundll32.exe E6F1873B.DLL, D9EBC318CBrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
    Ua?a2guard.exea-Squared antitrojan - can be run on demand but necessary in Startup if you prefer the a? 'Background Guard' real time protection feature
    ?AAACLEANAAACLEAN.INF??
    ?AAAKeyboard????
    NAAATraySaverTraySaver.exeSystem Tray management utility from Mike Lin which allows you to hide, show, restore icons that are lost in an Explorer crash, remove dead tray icons, minimize any window to the System Tray
    UAAKaak.exeAdvanced Anti-Keylogger - "Anti-spy software to prohibit operation of any keyloggers currently in use or presently being developed anywhere"
    UaaLDISCN32LDISCN32.EXELANDesk? Management Suite software component
    UaaLDTaskCompletionamclient.EXELANDesk? Management Suite software component
    XAAMSFree702Avengine.comAdded by the DELF.LJ TROJAN!
    XAAMSFree702sys.exeAdded by the BACKDOOR-CPC TROJAN!
    XAaouamee.exePurityScan/Clickspring adware
    XAappadprot.exeAdBlaster adware
    ?aauclientACNUpdater.exeAppears to be related to software from Accenture.com
    UAAWAd-Aware.exeAd-Aware anti-spyware tool from Lavasoft
    UAAWTrayAAWTray.exeSystem Tray access to Ad-aware from Lavasoft - popular spyware/adware removal tool
    ?ab EazySchedulerezsched.exe??
    NABBYY Community AgentCAGENT.EXEInstalled with the Optical Character Recognition (OCR) software that comes bundled with a Compaq A3000 all-in-one printer/scanner. Its function appears to be to link you to the internet in an attempt to buy the 5.0 version of the software
    UABCkeylogger.exeKeystroke logger/monitoring program - remove unless you installed it yourself!
    Xabcdefghabcdefgh.exeEPJ TROJAN!
    UABIT uGuruuGuru.exeABIT ?Guru - on motherboards incorporating the ?Guru processor this provides quick access to "hardware monitoring, overclocking, BIOS flashing and audio tweakin
    NABITEQabiteq.exeMonitoring utility for ABIT Motherboards. Displays system voltages, temperatures and fan speeds
    XAbrada WIN32abrada.exeAdded by the DERMON-G TROJAN!
    UAbsolute Shielddseraser.exeAbsolute Shield Evidence Eliminator - internet history eraser
    UAbsolute StartUp monitorASMon.exeAbsolute Startup - startup monitor from F-Group Software
    UAbsoluteShield Internet Erasercseraser.exeAbsoluteShield Internet Eraser - "protects your privacy by cleaning up all the tracks of your Internet and computer activities"
    XABsrabsr.exeAdded by the AUTOUPDER TROJAN!
    Xabsrmwsvm.exeSeekSeek search hijacker related - see here
    Xabtump3serch.exeLoads the executable for Lop.com. mp3serch.exe is the final version
    Xabtulopsearch.exeLoads the executable for Lop.com. lopsearch.exe is the beta version
    UAbyssWebServerabyssws.exeAbyss web server
    XAc97Soundsnddrv.exeDetected by Sophos as the SILLYFDC-A TROJAN!
    UAcBtnMgr_X63AcBtnMgr_X63.exe"Lexmark Scan & Copy Control Program" for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc
    UAcBtnMgr_X73AcBtnMgr_X73.exe"Lexmark Scan & Copy Control Program" for the Lexmark X73 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc
    UAcBtnMgr_X83AcBtnMgr_X83.exe"Lexmark Scan & Copy Control Program" for the Lexmark X83 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc
    UAcBtnMgr_X84-X85AcBtnMgr_X84-X85.exe"Lexmark Scan & Copy Control Program" for the Lexmark X84-X85 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc
    Uaccacc.exeAdvanced Call Center - "full-featured yet easy-to-use answering machine software for your voice modem"
    XACCDEFRAGINFO[path to worm]Added by the DARBY-O WORM!
    UAccelerateaccelerate.exeWebroot Accelerate - allows you to optimize Windows network registry settings in order to boost surfing speeds. Leave this enabled if you find it improves your connection
    XAccess Control Appwinsto.exeDetected by Kaspersky as the AGENT.DGO TROJAN! See here
    NAccess Ramp Monitorarmon32.exeMonitors your progress on the internet; hang-ups, connection speeds, internet congestion and traffic flow. It prevents some games from running also. To disable the Access Ramp Monitor (1) Open Windows Explorer (2) Open the Program Files folder (3) Open the MindSpring folder (4) Open the AccessRamp folder (5) Double-click on the ARMCfg32.exe file (6) Uncheck Enable Dialup Monitor and click OK (7) Restart the computer and try again
    XAccess WebControl[path to file]Added by the PPDOOR-M TROJAN!
    UAccessManagerAccessMgr.exePart of SmartPipes SecureSite software. "SecureSite enables rapid turnup and enhanced administration of VPNs. It automates and simplifies tasks for VPN design and policy management, access control management, and key management"
    XAccessMedia P2P Loaderamp2pl.exeMy AccessMedia toolbar related, stealth installed!
    UAccessoriesPlusclockplus.exeClock Plus, part of Accessories Plus allows you to select from dozens of alternatives for the Windows clock
    NAccessRamp Monitor01ARMon32a.exeFrom a visitor "Just wanted to provide you with some info on Access Ramp software installed with Verizon DSL accounts in those areas that use the Winpoet PPPoE software. The Access Ramp TSRs are installed as part of IP Insight software (can't remember the software maker). You can decline to install IP Insight during Winpoet setup, or go into Add/Remove programs uninstall IP Insight by hand if it's already installed. It really doesn't do a darn thing for you. It was intended to help DSL techs monitor QoS, but the backend part was never implemented (at least as of earlier this year). This will not affect the user's ability or inability to access their DSL service."
    NAccessRampLAN01ARUpld32.exeVersion of the AccessRamp Monitor01 entry for LAN connections - a history uploader. The key in turning it off is a file named ARUCfg32.exe. This file (ARUCfg32.exe) does not show up in the startup process. If you have this file, you can execute it and remove all the monitoring activities it does. Removing all the checks in all the boxes (both tabs) still calls ARUpld32.exe to start when you start the dial up. You can block it from sending info if you have Zone Alarm installed. Renaming the extension of ARUCfg32.exe to ARUCfg32.exe1 works. The ARUpld32.exe is not loaded when launching the dial up client. Written by IP Insight and also included with Earthlink Total Access 2003
    UAcctMgrAcctMgr.exeNorton? Password Manager - part of Norton SystemWorks 2004 - stores passwords and other personal information, and retrieves the data needed for email logins, shopping orders, banking, and other online activities - all from the safety of your own PC
    NAccuWeather.com? DesktopAccuWeatherDesktop.exeDesktop weather from AccuWeather
    Xaccwizz.exeaccwizz.exeAdded by the RULAND.A WORM!
    Xaccwizzz.exeaccwizzz.exeAdded by the RULAND.A WORM!
    Xacdllib3bcdlmem.exeAdded by the MAILBOT-BA TROJAN!
    NACDSeeACDSee8Pro.exeACDSee 8 photo software. Organize, manage, enhance, and share all your valued photo memories
    ?Ace bowsAce bows.exe??
    NAceGain LiveUpdateLiveUpdate.exe"AceGain LiveUpdate can help to automate and optimize product updates. AceGain LiveUpdate will automatically detect new patch updates, driver updates or full product updates and automatically download and install them according to user configuration"
    UAcer ePower ManagementAcer ePower Management.exePart of Acer Empowering Technology. "Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles, or to create their own customized profiles"
    NAcer ePresentation HPDePresentation.exeAllows you to connect your Acer laptop to a projector
    NAcer Product RegistrationACE1.exeAcer Product Registration - remove when registration is completed
    NAcer Tour ReminderReminder.exePopup reminder to take the tour of your new Acer laptop
    UAcerGotoAcerGoto.exeAcer Computer "Goto Drive" Cold Swap Driver - a swappable second disk drive provides convenient backup of large files, or easy importation of data from user's previous computer
    UAcerNotebookManageralmxptray.exeSystem Tray access on some Acer Notebooks to give faster access to system settings
    UAcerPowerkeyPowerkey.exePowerKey utility for Acer TravelMate notebook PCs. Allows the user to quickly switch between different power schemes by pressing Fn+F3
    XAcess2007aaccess2007a.exeAdded by the GAOBOT.PQA WORM!
    XAceu[random filename]PurityScan/Clickspring adware
    YacEventServacevtsrv.exeActivCard Gold from ActivIdentity, Inc. Smart card-based strong authentication software - for photo IDs, proximity badges for facility access and as digital identification and authentication
    UAClntUsrAClntUsr.exeAltiris AClient Service Windows Tray Icon
    NAcme.PCHButtonpchbutton.exeUsed by HP Instant Support
    UACMonitor_X63ACMonitor_X63.exeButton monitor for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Works in conjuction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X63.exe"
    UACMonitor_X73ACMonitor_X73.exeButton monitor for the Lexmark X73 all-in-one multifunction printer/copier/scanner. Works in conjuction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X73.exe"
    UACMonitor_X83ACMonitor_X83.exeButton monitor for the Lexmark X83 all-in-one multifunction printer/copier/scanner. Works in conjuction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X83.exe"
    UACMonitor_X84-X85ACMonitor_X84-X85.exeButton monitor for the Lexmark X85-X85 all-in-one multifunction printer/copier/scanner. Works in conjuction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X85-X85.exe"
    Xacocashfastdown.exeAdult content dialler
    Xacocashfastdown.exeAdult content dialler
    UAcombo3dmouseAcombo3d.exeMouse driver - required if you use non-standard Windows driver features
    XAcontiaconti.exeAdult content dialler
    Uacousticacoustic.exeControl panel program for Philips Acoustic Edge soundcard. Not required unless changed settings aren't retained
    Nacpartagpart11.exeProgram for finding trucks on-line
    XAcrobatacrmon32.exeAdded by the SMALL-ECT TROJAN!
    UAcrobat Assistant *.*ACROTRAY.EXEEssential for creating PDF files with Adobe Acrobat and Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the "U" recommendation. *.* represents the version
    XAcrobat Readacroup32.exeAdded by the VANBOT-BQ TROJAN!
    NAcrobat Speed Launchacrobat_sl.exeSpeeds up the time it takes to load Adobe's Acrobat PDF creation and management tool. From version 7.0 onwards
    UACROMOUSEACROMAPP.exeRelated to ACROMOUSE Laser mouse control
    UAcronis Popup BlockerRunDll32.exe [path] Blocker.dll, RunPart of Acronis Privacy Expert - anti-spyware and security suite
    UAcronis Scheduler Helperschedhlp.exePart of Acronis True Image backup software. Co-operates with the "schedul2.exe" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images
    UAcronis Scheduler2 Serviceschedhlp.exePart of Acronis True Image - backup software. Co-operates with the "schedul2.exe" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images
    UAcronis True ImageTimounterMonitor.exePart of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archive
    NAcronis True Image MonitorTrueImageMonitor.exePart of Acronis True Image - backup software. Can be disabled without affecting TrueImage
    NAcronis TrueImage MonitorTrueImageMonitor.exePart of Acronis True Image - backup software. Can be disabled without affecting TrueImage
    UAcronisTimounterMonitorTimounterMonitor.exePart of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archive
    NAcronisTrueImage MonitorTrueImageMonitor.exePart of Acronis True Image - backup software. Can be disabled without affecting TrueImage
    UAct! PreloaderAct8.exeSage Software's ACT! "enables individuals and small business customers to instantly access key contact and customer information, manage and prioritize activities, and track all contact-related communications so you can grow productive business relationships"
    NAction Manager 32am32.exeAssociated with a Plustech scanner. Small utility that runs in the background for doing fax/copy/etc. Available via Start -> Programs
    ?ActionAgentactionagent.exe"A COM server that runs on the client as part of the Dell OpenManage Client Instrumentation 6.x package; provides a simple method for a remote administrator to perform actions on the instrumented client". Is it required?
    NActivationActivation.exePart of Microsoft Money
    UActivboardMMKeybd.exePackard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock, Caps Lock, Scroll Lock keys
    XActive Bit Stationabs.exeAdded by the MYTOB.BZ WORM!
    NActive CPUacpu.exeActive CPU - "easy to use tool for Windows 95/98/ME/NT/2000 that enables you to watch a graphical representation of your CPU's activity"
    UActive Desktop CalendarADC.EXEXemiComputers Active Desktop Calendar
    UActive Email Monitoraem25.exeActive Email Monitor checks multiple accounts for email, serves as a SPAM filter and can also protect you from harmful items that can be sent via email
    UActive shieldActiveshield.exeActive Shield is "an heuristic screen that actively protects your computer from trojans, spyware, adware, trackware, dialers, keyloggers, and even some special kinds of viruses"
    XActiveDesktopsystray32.exeAdded by the DABOOM WORM!
    XACTIVEDSACTIVEDS.EXEAdded by the OPASERV.T WORM!
    NActiveEyesActiveEyes.exeActiveEyes from TFI Technology is a small utility that you can use to liven up your desktop. It follows your mouse around and can tell you how far your cursor has travelled or point out where the cursor is. It's small, it's free and comes with a range of options and animations. Not needed - if unavailable via Start -> Programs, create your own shortcut
    UActiveKeys.AAB635BD7D054a37A576akeys.exe"Active Keys is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action"
    UActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
    UActivePlusactiveplus.exeInteractive Agents Plugin for Messenger Plus! (MSN Messenger add-on)
    XActiveScan AntivirusActiveScan.exeAdded by the RBOT-FKQ WORM!
    XActiveScript32nod.exeAdded by the SOHANA-AJ WORM!
    YActiveShieldMCVSSHLD.EXEMcAfee VirusScan On-line. See also the McAgentExe entry
    UActiveSpeedAS.exeAscentive ActiveSpeed Internet Optimizer
    XActiveSyncwcescom32.exeAdded by the MANCSYN-E TROJAN!
    NActiveWordsAWMonitor.exeActiveWords from ActiveWord Systems, Inc. Like macro programs, ActiveWords sits in the background and watches as you type. When it recognizes that you?ve typed an ActiveWord, it takes the associated action, such as replacing your keystrokes with the text you?ve defined
    XActiveX File Registration Servicefilereg.exeAdded by the RBOT-DVD WORM!
    XActiveX Streamermsgfix.exeAdded by the SDBOT.NQ WORM!
    XActiveXUpdatesvcss.exeAdded by a variant of the DEDLER.C TROJAN!
    UActivityactik.exeActivityKey Keystroke logger/monitoring program - remove unless you installed it yourself!
    NActivSurfbackweb*****.exePackard Bell ActivSurf - automatically detects an internet connection and downloads any available updates
    UActMakerActMak25.exe"ActMaker mouse and keyboard toolkit can record the daily operation of your computer and reduce your workload. You don't need to do any coding, nor are you required to know a lot about the computer"
    UActMakerActMaker25.exeActMaker mouse and keyboard toolkit can record the daily operation of your computer and reduce your workload
    UACTrayACTray.exeSystem Tray icon for ThinkVantage Access Connections - "allowing users to seamlessly switch between wired and wireless environments, managing security settings, printers, home page and other location-specific settings automatically"
    UActual Window MinimizerActualWindowMinimizerCenter.exeActual Window Minimizer - "allows minimizing any window to task tray notification area or to the edge of the screen"
    XACTX1v1201.exeAdded by the VB.IS TROJAN!
    UACUACU.exeAtheros wireless Client Utility
    UACU_QSBACU.exeAtheros wireless Client Utility
    UACWLIconACWLIcon.exeRelated to IBM ThinkVantage Connectivity Solution
    UAd Blockerblocker.exeAd Blocker - blocks popups, and also removes banners, image ads and flash ads
    UAd Blocker ProAd Blocker Pro.exeAd Away popup and banner remover
    UAd MuncherAdMunch.exeAd Muncher removes adverts, pop-ups and general annoyances in your browser, file-sharing and messenger programs. Causes conflicts with Outlook, game sites and web-building applications
    ?Ad Online Guideadonlineguide.exe??
    UAd-awareAd-aware.exeAd-aware from Lavasoft - popular spyware/adware removal tool
    XAd-AwareAd-Aware.exeAdded by the RBOT-ADJ WORM! Note - this is not the popular Ad-aware spware/adware removal tool and is located in the WinntSystem32 or WindowsSystem32 directory
    XAd-Eliminatorad-eliminator.exeAd-Eliminator spyware remover - not recommended, see here
    UAd-MuncherADMUNCH.EXEAd Muncher removes adverts, pop-ups and general annoyances in your browser, file-sharing and messenger programs. Causes conflicts with Outlook, game sites and web-building applications
    UAd-Protectad-protect.exeAd-Protect spyware and spam monitoring tool
    UAd-watchAd-watch.exePart of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system
    UAD2KClientAD2KClient.exeExecutable for Active Disk from Iomega disk - allows software applications to be run directly from an Iomega Zip? disk. Required if you wish the applications to launch on insertion of a disk
    NAdaptec DirectCDDirectcd.exeDirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
    NAdaptecDirectCDDirectcd.exeDirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
    XAdAwarewini.exeAdded by the RBOT-XN WORM!
    UAdaware Bootupad-aware.exeAd-aware from Lavasoft - popular spyware/adware removal tool
    XAdaware lptt01adaware.exeRapidBlaster variant (in a "Adaware" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Lavasoft Adaware
    XAdaware ml097eadaware.exeRapidBlaster variant (in a "Adaware" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Lavasoft Adaware
    UAdBinAdBin.exeAdBin - "Free and easy solution to managing your Window's hosts file. A fun way to block ads"
    XAdd**.exe [* = random char]Add**.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
    XAdd**32.exe [* = random char]Add**32.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
    XAddClassAddClass.exeCoolWebSearch Addclass parasite variant
    XAddClass[Installation_Path]Added by the STARTPAGE.F hijacker
    XAddClass[path to trojan]Added by the SECDL-A TROJAN!
    UAdDeleteAdDelete.exeBanner advertisment blocker
    XAdDestroyerAdDestroyer.exeVirtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see here
    XADDITIONAL Servicespkgadd.exeAdded by a variant of the IRCBOT TROJAN!
    ?addproxyaddproxy.exeRelated to Adobe Photoshop
    ?ADGADG.exe SoundBlaster Audigy related?
    NADGJdetADGJDet.exeAdded with SoundBlaster Live! or Audigy soundcards for headphone autodetection
    XaDiradirss.exeAdded by the SPAMSRV-E TROJAN!
    YAdirasAdiras.exeADSL USB modem related
    Xadirkaadirka.exeAdded by the TIBS-QT TROJAN!
    UAdKillerAD Defender.exePart of Advanced Spyware Remover anti-spyware tool
    Xadlhidppsncc32.exeDetected by Kaspersky as the SLAPER.AI TROJAN! See here
    XADM Library Loaderadmlib32.exeAdded by a variant of the SDBOT TROJAN!
    XAdmanager ControllerAdManCtl.exeAdware, probably a Windupdates variant
    XAdmilli ServiceAdmilliServ.exeWindupdates adware variant
    XAdministratorsvchost.scrAdded by the NOVACAL TROJAN!
    XAdministratorwinlogon.exeAdded by the RUBBLE-C WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
    XAdministrator di DagoDago.exeAdded by the PUNYA-B WORM!
    XAdminSoftsysfile.vbsAdded by the STARGRUB-A WORM!
    Uadmtray.exeadmtray.exeRelated to Acer Inc. destop tray
    XAdobeAdobe.exeAdded by an unidentified VIRUS, WORM or TROJAN!
    XAdobesysconfig.exeAdded by an unidentified WORM or TROJAN!
    Xadobegam.exeAdded by an unidentified WORM or TROJAN!
    XAdobesysbat32.exeAdded by the LOWZONES.T TROJAN!
    XAdobezteam.exeAdded by an unidentified TROJAN!
    NAdobe AcrobatREADER~1.EXESpeeds up the time it takes to load the Adobe Reader application. Your choice, but not required for Adobe Reader to function properly
    XAdobe Acrobat Distiller Applicationacrotray.exeAdded by the RANDEX.DFJ WORM!
    XAdobe Acrobat Reader CFG[random filename]Added by a variant of the RBOT WORM!
    NAdobe Acrobat Speed Launcheracrobat_sl.exeSpeeds up the time it takes to load Adobe's Acrobat PDF creation and management tool. From version 7.0 onwards
    XAdobe Filter Platformafilterplatform.exeAdded by the RBOT-OP WORM!
    UAdobe Gamma LoaderAdobe Gamma Loader.exeAdjusts monitor colours across all programs, including Photoshop. It is needed by some graphics professionals who want their monitor calibrated. Most home users will not need it. In my case I can verify this as Photoshop loads fine
    NAdobe Photo Downloaderapdproxy.exePart of Adobe's Photoshop Album or Photoshop Elements packages - starts each time you connect an external image device to your PC (see here)
    NAdobe Reader Speed LaunchReader_sl.exeSpeeds up the time it takes to load the Adobe Reader application. Your choice, but not required for Adobe Reader to function properly
    NAdobe Reader Speed LaunchREADER~1.EXESpeeds up the time it takes to load the Adobe Reader application. Your choice, but not required for Adobe Reader to function properly
    NAdobe Reader Speed LauncherReader_sl.exeSpeeds up the time it takes to load the Adobe Reader application. Your choice, but not required for Adobe Reader to function properly
    UAdobe Reader SynchronizerAdobeCollabSync.exeAdobe Synchronizer - installed along with Adobe Reader 8.x. "Synchronizer is a small application that runs in the background, providing synchronization of document reviews and Tracker subscriptions so that your data is available when you need it." See the link for more information
    UAdobe Version Cue CS2VersionCueCS2Tray.exeFile manager that's part of Adobe Creative Suite 2 - "find files fast, track versions across applications, link files together, and share them in creative collaboration without fear of overwriting someone else's work"
    XAdobeAadobes.exeAdded by the FLOOD.BA TROJAN!
    XAdobeFontsfonts.htaBrowser hijacker - redirecting to Hugesearch.net
    Xadobemgradobemgr.exeAdded by the ADCLICKER TROJAN!
    XAdobeReadermsni.exeAdded by the RBOT.DAO TROJAN!
    XAdobeReaderPromsnxpsp.exeAdded by the RBOT-ASK or RBOT-AUS WORMS!
    XAdobeReaderProntkernell32.exeAdded by the RBOT-ATY WORM!
    XAdobeReaderPromsnserve.exeAdded by the SDBOT-AKH WORM!
    XAdobeReaderProupdt.exeAdded by the IRCBOT-VQ WORM!
    XAdobeReaderProfessionalmsx64.exeAdded by the RBOT-GAT WORM!
    XAdobeReaderProssysmsn.exeAdded by the RBOT-BGH WORM!
    NAdobeUpdaterAdobeUpdater.exeAutomatic updater for Adobe software - run manually
    NAdobeVersionCueVersionCueTray.exe"An exclusive feature of the Adobe? Creative Suite, Version Cue? helps you find files fast, track multiple versions of your files, and share your files for creative collaboration"
    Xadodemasteradodemaster.exeDownloader of Korean origin, detected as ADOD.28672
    XAdope File Managerlsasv.exeAdded by an unidentified WORM or TROJAN!
    Xadpadp.exeSpyware installed by Net2Phone, Limewire, Cydoor, Grokster, KaZaa, etc
    XAdPopupdcf5678.exeAdded by the AGENT-FZ TROJAN!
    Xadprotadprot.exeAdBlaster adware
    NADQuickAccessAdtray.exeAfter Dark for Windows. Screen saver creation program produced before screen savers became integrated into Win95
    XADriverwindrv.exeAdded by the DELF.WG TROJAN!
    XAdRoarUpdateARUpdate.exeAdRoar adware updater
    XAdRotator.Application[path to csrss.exe]Added by the SMALL-AQ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
    XAdRotator.Applicationservices.exeFakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in an "Inetsrv" subfolder
    XADS Adware RemoverADS Adware Remover.exeADS Adware Remover - not recommended, see here
    XAdsBlockerstopAds.exeReported as DILAER.DW by NOD32
    UAdsCleanerAdsCleaner.exe"AdsCleaner is a powerful ad blocking software designed to stop ads (block banners ad, kill popup), guard your online privacy"
    UADServiceADService.exePart of Iomega's Active Disk - allows software applications to be run directly from an Iomega Zip? disk. Required if you wish the applications to launch on insertion of a disk
    UAdsGoneAdsgone.exeAdsGone - pop-up stopper
    NADSL Diagnostic Toolsmapiicon.exeSystem tray access to ADSL modem diagnostic tools. Available via Start -> Programs
    ?ADSLSYSTEMTRAYSystemtrayV100B.exeApparently Annex A ADSL modem related. What does it do and is it required?
    YAdslTaskBarrundll32.exe stmctrl.dll, TaskBarISP software, initializes DSL modem
    XAdslTaskBarstaskmng.exeAdded by the RBOT-AXZ WORM!
    ?ADSL_A2A2InstalledAssociated with an Integrated Telecom Express (ITeX) ADSL driver installation. What does it do and is it required?
    YADSSADSS.exeADSS is part of Access Denied security and privacy software (Access Denied Security Server) that monitors power status and provides some other services for Screen Guard. Important to keep its running while using Access Denied
    Xadstartupautomove.exeAdlogix adware variant
    XadstartupAdstartup.exeAdlogix adware variant
    XAdStatus ServiceAdStatServ.exeWindUpdates AdStatus Service adware
    UAdSubtractadsub.exeAdSubtract blocks ads, cookies, pop-up windows, animations, music, and more. Can be disabled from within AdSubtract. Available via Start -> Programs. Now superseeded by Trend Micro AntiSpyware
    Xadtech2005adtech2005.exeDetected by Kaspersky as the STARTPAGE.AW TROJAN!
    Xadtech2006adtech2006.exeDetected by Kaspersky as the VB.KC WORM!
    XAdtools ServiceAdTools.exeWindupdates Adware
    ?ADUadu.exeRelated to Cisco Aironet wireless products. What does it do and is it required?
    XAdultXAdultX.exeAdult content dialler and hijacker
    XAdult_ChatAdult_Chat.exeAdult content dialler
    XAdult_Chat1Adult_Chat1.exeAdult content dialler
    XAdUpdatersysupudt.exeUnidentified adware downloader/updater
    UADUserMonADUserMon.exePart of Iomega's Active Disk - allows software applications to be run directly from an Iomega Zip? disk. Required if you wish the applications to launch on insertion of a disk
    XAdvanced DHTML Enableexo32.exeAdded by the RANCK-FI TROJAN!
    XAdvanced DHTML Enable[path to trojan]Added by the AGENT.GLQ TROJAN!
    XAdvanced Internet Protocolcerf.exeAdded by a variant of the SPYBOT WORM!
    XAdvanced Protection Systemadvpsys.exeAdded by a variant of the RBOT WORM!
    UAdvanced Spyware RemoverAsr.exeAdvanced Spyware Remover anti spyware tool
    XAdvanced Tool Checksadvchks.exeAdded by a variant of the RBOT WORM!
    NAdvanced Tools CheckADVCHK.EXEChecks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget
    UAdvanced Uninstaller PRO Installation Monitormonitor.exeInnovative Solutions Advanced Uninstaller PRO - "easy-to-use suite for uninstalling applications and keeping your computer fast, clean, and in its best shape"
    XAdvancedCleaner FreeUADC.exeAdvancedCleaner misleading security software - not recommended, see here
    XAdVantageAdVantage.exeMediaAdVantage adware
    Xadvap32[path to trojan]Detected by Trend Micro as the MUTANT.AT TROJAN! See here
    XAdvapiAdvapi.exeAdded by the NETDEVIL.12 WORM!
    NADVCHKADVCHK.EXEChecks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget
    UAdvertising KillerAkiller.exeAdvertising Killer - popup stopper
    Xadvmon32advmon32.exeAdded by a variant of the CRYPTER.C TROJAN!
    UAdware Agentadware agent.exeAdware Agent popup blocker
    XAdware SpyAdwareSpy.exeAdware Spy adware remover - not recommended, see here
    UAdwareAlertAdwareAlert.ExeAdware program, previously not recommended (see here). It has now been delisted, so make sure you have the latest version
    XAdwareDeleteadwaredelete.exeAdwareDelete adware remover - not recommended, see here
    XAdwareKiller_schedulesschedules.exeEAdwareKiller spyware remover - not recommended, see here
    XAdwareKiller_traytray.exeEAdwareKiller spyware remover - not recommended, see here
    XAdwareProMFCAd-Ware Pro.exeAd-Ware Pro spyware remover - not recommended, see here
    XAdwareRemover2007AdwareRemover2007.exeAdwareRemover2007 spyware remover - not recommended, see here
    ?Aeiwlsta.exeAeiwlsta.exeIBM High Rate Wireless LAN Adapter driver. Is it required?
    NAELaunchAELaunch.exeAudio Applications Launcher for the Philips Acoustic Edge soundcard
    XAERVICESNAERVICESN.exeAdded by the RANDON-AO WORM!
    NAeXAgentLogonAeXAgentActivate.exeAltiris Agent transmits information about your machine for the purpose of asset management and deployment
    ?AeXSWDUsrAeXSWDUsr.exeAltiris Express NS Client Manager software. Is it required?
    UAEZBProcaptezbp.exeIBM Aptiva keyboard customizer - enables certain special buttons on keyboard for CD operation, volume control, and few quickstart buttons. Keyboard will work without it but you lose the special functions
    UAFAFilterwindefault.exeAFAFilter - internet filter software
    Xafskfask8fsfjasj8.exeAdded by the ONLINEG-L TROJAN!
    NAGEIA PhysX SysTrayTrayIcon.exeSystem Tray access to display properties for AGEIA PhysX graphics cards. Unless you change your desktop resolution, etc, regularily use Control Panel -> Display Properties or right-click on the desktop
    NAgentAgent.exeCyberlink's Power VCR II 3.0 is a TV tuner recording utility. If you want to schedule recordings you'll need this, otherwise can be disabled. Available via Start -> Programs
    XAgentalsys.exeAdded by the DREF-V VIRUS!
    Xagentppl.exeAdded by the DREF-U VIRUS!
    XAgent Browser[random filename]Added by the PPdoor.M-bdr backdoor TROJAN!
    XAgent Explorer[random filename]Unidentified adware
    ?AgenteRemupd.exePart of Panda Antivirus . Is this an update reminder (guess because of the name), virus definition update reminder or something similar?
    Xagentsvragentsvr.exeMalware, detected by Kaspersky as AdWare.Monker.a. NOTE: do NOT confuse with the Microsoft Agent Server application of the same name as described here - the legitimate file will always be located in the WindowsMsagent folder
    UAgfaCLnkAgfaCLnk.exeFor Agfa digital cameras connected via USB. Enables Windows to access the contents of the memory stick (while the stick's still on the camera) via a virtual drive
    Xagpagp32.exeAdded by the GAOBOT.SY WORM!
    YAGRSMMSGAGRSMMSG.exeIBM AMR modem driver
    NAGSatelliteAGSatellite.exeProgram from AudioGalaxy that lets you download some MP3s from their server. Available via Start -> Programs
    Uahfpahfp.exeAdvanced Hide Folders - "is powerful file security program. It allows to hide folders or hide files. Advanced Hide Folders is very useful to keep your personal data away from others. Others will not know where your personal files exist and they will not be able to accidentally view, delete or modify them either"
    Uahfprogahfp.exeAdvanced Hide Folders - "is powerful file security program. It allows to hide folders or hide files. Advanced Hide Folders is very useful to keep your personal data away from others. Others will not know where your personal files exist and they will not be able to accidentally view, delete or modify them either"
    YAHNSDAhnSD.exeAhnLab V3 antivirus updater - leave enabled unless you manually update on a regular basis
    ?AHNUEAHNUE.exe??
    Xahostahost.exeAdded by a variant of the SDBOT WORM!
    NAHQInitahqinit.exePart of AudioHQ for the Soundblaster Live!. Appears as though it makes the AudioHW toolbar drop down from the top of the desktop and isn't required
    XAhstiebs.exePurityScan/Clickspring adware
    XAHU[path to worm]Added by the ANACON-B WORM!
    XAHUANACON.EXEAdded by the NACO.A WORM!
    Xahui32.exeahui32.exeAdded by the CERTIF-M TROJAN!
    UAi NapAiNap.exePart of the "Ai Suite" utility supplied with some Asus motherboards. "With AI Nap, users can instantly snooze your PC without terminating the tasks. System will continue operating at minimum power and noise when user is temporarily away"
    NAi Quicker HelpAsRc.exeASUS DH Remote media portal launcher for their Digital Home range of motherboards that are designed for users to control the computer at a distance away, such as the M2N DH. "ASUS DH Remote is a convenient PC remote controller that gives users unprecedented control over their PCs from the comfort of their couches"
    XAicatuaa.exePurityScan/Clickspring adware
    XAidattuh.exePurityScan/Clickspring adware
    XAidaeetu.exePurityScan/Clickspring adware
    ?AidemHotKeyDVMAIN.EXEKeyboard related
    ?AidemHotKeyKEYAPP.EXEKeyboard related
    Uaiepkaiepk2.exeAnother IE Popup Killer - pop-up stopper
    NAIMaim.exeAOL Instant Messenger. If connected to the internet, automatically runs up AIM. Convenience more than anything. Available via Start -> Programs
    UAIMAIM+.exeAIM plus - a free add-on to AOL's Instant Messenger for Windows from Big-O Software
    XAIM Instant Message Cookies[random filename]Added by the RBOT-AFV WORM!
    NAIM LoggerAIMLogger.exeAIM Logger - saves AIM (AOL Instant Messenger) conversations to log files. Can be started when you are using AIM
    XAim Pluginaimplugin.exeAdded by the GUAP-F WORM!
    XAIM reminderAIM reminder.exeAdded by the BUDDY TROJAN!
    NAim6AOLLaunch.exeAOL Instant Messenger - start it when you want to use it
    NAim6aim6.exeAOL Instant Messenger - start it when you want to use it
    XAIM95 Startupaim95.exeAdded by the AGOBOT.AEE WORM!
    Xaimaol lptt01aimaol.exeRapidBlaster variant (in a "Aimaol" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
    Xaimaol ml097eaimaol.exeRapidBlaster variant (in a "Aimaol" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
    Uaimb.exeaimb.exeIMSufSentinel is a spy program which can record IM conversations, log keystrokes, record URLs visited, and take screenshots. If you didn't install this yourself remove it
    NAimingClickAimingClick.exeAimingClick from AimingTech. Web searching tool. Available via Start -> Programs
    UAIMProaimpro.exeAIM Pro - secure instant messaging, video conferencing, on-line meetings and desktop and file sharing
    NAIMster??Peer to Peer (P2P) file sharing client that runs over the AOL Instant Messenger network. Available via Start -> Programs
    NAIMWDInstallAIMWDInstall.exeVersion of the WildTangent on-line games installer that came with versions of AOL Instant Messenger. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
    YAiptek Graphics Tablet (USB)atwtusb.exeUSB interface for Aiptek Graphics Tablet (USB)
    Xaircityaircity.exeRelated to "Prutect" malware from e2Give
    UAirPort Base Station AgentAPAgent.exeAirport Base Station Agent utility for Apple's AirPort wi-fi basestations. "Wireless solution for home, school, and business. As it blankets your space with a blazing-fast, secure wireless network, it opens up a world of possibilities for home entertainment, backups, printing, and more"
    XAKEYNAMEWinServ.exeAdded by the EVILBOT.C TROJAN!
    Uakeysakeys.exe"Active Keys is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action"
    Xakgkagaksad9fsakfask9.exeAdded by the ONLINEG-M TROJAN!
    UAKillerakiller.exeAdvertising Killer - popup stopper
    Xala.exeala.exeAccess Lock is a system-tray security utility you can use to secure your desktop when you are away from your computer
    UAlarm ManagerAlarmapp.exePalm alarm event reminder that coordinates what is on your Palm with settings on your desktop
    ?AlarmWatcherAlarmWatcher.exeAssociated with SynTPEnh and SynTPLpr which are from Synaptics for touchpads on laptops. What does it do and is it required?
    NAlbum Fast StartABMTSR.EXEScanner software, not required for scanner to work
    ?AlcFDMonitorALCFDRTM.EXERealTek related - Real-Time SPDIF-in Monitor for nVidia chipset - is it required in startup?
    ?ALCFDRTM16ALCFDRTM16.comRealTek related - Real-Time SPDIF-in Monitor for nVidia chipset - is it required in startup?
    XAlchemAlchem.exeClickAlchemy adware
    UAlcmtrAlcmtr.exeInstalled with hardware drivers for a Realtek AC97 audio device. It's believed that Realtek uses this file in order to data about the customer. Some users report problems with their on-board sound if this is disabled - hence the "U" recommendation
    UAlcoholAlcohol.exeAlcohol 120% - CD/DVD emulation/writing/copying software
    UAlcohol AutorunAlcohol.exeAlcohol 120% - CD/DVD emulation/writing/copying software
    UAlcoholAutomountaxcmd.exeAlcohol 120% is a powerful Windows application that makes it easy to create backups of DVDs* and CDs. In addition, the program lets you store your most used CDs as images on your computer, so you can call them up at the click of a button. This part automounts images disc images
    ?Alcom PCL CaptureFMW_PCAP.EXE??
    NAlcWzrdALCWZRD.EXERealTek High Definition audio driver related - detects new devices when plugged in, then pops up a dialog box. If everything works as expected you should be able to disable this one
    UAlcxMonitorAlcxmntr.exeInstalled with hardware drivers for a Realtek AC97 audio device. It's believed that Realtek uses this file in order to gather data about the customer. Some users report problems with their on-board sound if this is disabled - hence the "U" recommendation
    Xaldefr ere servicetay0x.exeAdded by the RBOT-XS WORM!
    Xalerteralerter.exeAdded by the MAHA.F TROJAN!
    XAlevirAlevir.exeAdded by the OPASERV-A WORM!
    XAlevirOld[worm filename]Added by the OPASERV WORM!
    NAlexaalexa.exeRelated to Alexa. Note - collects and stores information about the web pages you view, the data you enter in online forms and search programs and, with versions 5.0 and higher, the products you purchase online whilst using the toolbar. Although Alexa state's they do not attempt to analyze the data it may collect about you to determine who you are, some of your information collected by the software is personally identifiable. Please read the Privacy Policy. Not Recommended
    XAlexaToolbaralt.exeReported as the DELF.EB hijacker by Ewido Security Suite
    XAlfaCleanerAlfaCleaner.exeAlphaCleaner is now a stealth install using exploits on unpatched systems. Seen alongside RazeSpyware
    UAlfaClock ClassicAlfaClock.exeAlfaClock from AlfaSoft Research Labs - "enhances your taskbar clock (tray clock) with fully customizable clock display, alarms, time synchronization and more"
    UAlfaClock2AlfaClock2.exeAlfaClock2 - tray/desktop clock and time synchronization software
    ?ALFY AccelleratorAlfyAC~1.exe??
    XALG.EXEiexplorer .exeAdded by the DEMOTRY-B WORM!
    XALG32ALG32.EXEAdded by the STARTPAGE.K hijacker
    Xalgchk.exealgchk.exeDetected by Kaspersky as the VB.ATE TROJAN!
    XALGUALGU.EXEAdded by the CWS-I TROJAN!
    UALi5289ALi5289.exeRelated to Uli Integrated Drivers from Uli Electronics Inc
    NAlias SketchBook SnapshotALIASS~2.EXEScreen-capture utility for Alias Sketchbook
    NAlienAutopsyTest_BS.exeAlienware computer technical support software
    YALiSndMgrALiSndMg.exeALi AC97 Sound driver
    ?AliUSBfixGREENMK.exeMay be realted to a USB 2.0 PCI card - the IOgear GIC220OU?
    XAlive SYstemscchost.exeAdded by the TOFDROP-B TROJAN!
    XAlive SYstemscchostc.exeAdded by the TOFDROP-B TROJAN!
    Xalkasr?????.exeAdded by the BALKART TROJAN!
    UAll Aboard Statusstswin.exeAll Aboard! Internet Connection Sharing status icon
    XAll Sea screen saverTaskTray.exe"Free screensaver", installs lots of foistware. See here. Get rid of it
    XAll Sea web linkFWLink.exe"Free screensaver", installs lots of foistware. See here. Get rid of it
    NAllerCalcAllerCalc.exeAllerCalc is an expression calculator which allows you to directly enter an expression to be evaluated. Can be started manually
    XAllopassw[path to trojan]Added by the RANKY.CU TROJAN!
    UAllSeeingEyease.exeAll-Seeing_Eye security software - "monitors everything that takes place on your computer, and alerts the user as soon as anything suspicious or out-of-the-ordinary is happening, providing the user with alternatives for possible actions"
    UallSnapallSnap.exe"allSnap is a small system tray app that makes all top level windows automatically align like they do in programs such as Winamp or Photoshop"
    UAllToTrayALLTOTRAY.EXEAlltoTray from DNTSoft - minimize any program to your System Tray
    XAlogrithm Link Queuealq.exeAdded by a variant of the SDBOT WORM!
    UAlogservAlogserv.exeFrom McAfee VirusScan for logging scanning activities. In some cases, if left running it can cause CPU % usage to go between 5-95% or go to and stay at 100%. Disabling it impacts on the reported last scan date. It is reported to cause jerky graphics response in many games. As of version 6, this is a critical component of McAfee and disabling it can cause a PC to lock up
    UALPassALPass.exeALPass password manager
    Xalphasvchost.exeAdded by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
    YAlps Electric USB ServerMonserv.exeAlps Electric USB Server - required according to this article
    UAlpsPointApoint.exeTouchpad software for laptop PC's. For instance it is found on the Panasonic and Sony Vaio machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work
    ?ALServALServ.exeAltec Lansing AMS speaker related. What does it do and is it required?
    XAltnetpoints manager.exeAltnet TopSearch adware
    XAltnetPointsManagerpoints manager.exeAltnet TopSearch adware
    UAltoMB_serviceAltoMBsrv.exeAlto Memory Booster from Alto Software - boost the computers performance via more intelligent and efficient memory management. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
    UALTOOLSAccessL.exeALTools family of PC utilities
    XAltPaymentsAltPayments.exeWeirdOnTheWeb adware
    NALU Scheduler ServiceALUSchedulerSvc.exeSymantec LiveUpdate scheduler for programs such as Norton AV or Internet Security
    UALUAlertALUNotify.exeNotification reminder for Symantec's LiveUpdate. Leave enabled unless you manually run LiveUpdate on a regular basis
    NAluria Security CenterSecurityCenter.exeAluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here
    UAluria's Pop-Up Stoppereps.exeAluria Pop-Stopper
    NAluria's Spyware EliminatorASE.exeAluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here
    UAlwaysOnTopMakerAlwaysOnTopMaker.exeAlways On Top Maker - utilty to enable an application to always be displayed "on top" of others on the desktop
    NAlwaysReady Power Message APPARPWRMSG.EXERelated to HP and Compaq Desktop PCs. Read this article
    XAmazingTensAmazingTens.exePremium rate adult content dialler
    UAMD PowerNow!GemBack.exeAMD PowerNow! - "an innovative solution available on all AMD mobile processor-based notebooks that can effectively increase notebook battery life, while delivering performance on demand"
    Yamd_dc_optamd_dc_opt.exeAMD Dual-Core Optimizer - "can help improve some PC gaming video performance by compensating for those applications that bypass the Windows API for timing by directly using the RDTSC (Read Time Stamp Counter) instruction"
    NAmerica Online *.* Tray Iconaoltray.exePuts AOL icon in System Tray (*.* denotes version if present). Connect to AOL via the desktop shortcut or Start -> Programs
    NAME_CSArundll32 amecsa.cpl, RUN_DLLLoads ADSL modem Control Panel applet
    UAModemLockDownModemLockDown.exeModemLockDown - allows you to supervise internet access by disabling the modem, protects againt dialers accessing dial-up connections, etc
    YAmonAMON.EXEMonitoring part of Eset's NOD32 virus-scanner
    YAmonitoramon.exeTiny Personal Firewall
    UAMP WinOFFwinoff.exeWinOFF is " a utility designed to shut down Windows computers automatically, in a fully configurable way"
    UAMSGAmsg.exePart of the IBM ThinkVantage Productivity Center. "The Message Center sends automatic notification on ThinkVantage Technologies integrated with your system. Once you're online"
    Xamsgupdateams.exeAdded by a variant of the MAILBOT TROJAN!
    NAMSNamsn.exeaMSN Messenger is a multiplatform MSN messenger clone
    Xamsnamsn.exeAdded by the BANKER-BNZ TROJAN!
    Xamvaamvo.exeAdded by the SILLYFDC-BR WORM!
    NAnapod Manageranamgr.exeAnapod Explorer "is the most advanced Windows iPod software available, offering iPod management through full Windows Explorer integration under My Computer"
    Xanbv32nabv32.exeAdded by the TITOG.C WORM!
    Xangeleyesmsdll.exeDetected by Kaspersky as the VB.PI TROJAN! See here
    YANIWZCS2ServiceWZCSLDR2.exeALPHA Networks wireless driver
    ?ANIWZCSServiceWZCSLDR.exeD-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity
    ?AnnotateCheckAnnCheck.exeGenius Wizard Pen Tablet driver related. Is it required?
    NAnnouncementsAnnclist.exeMS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
    NAnntextAnntext.exeCaere Pagekeeper text annotation server
    UAnonymityGatewayAnonymity Gateway.exeAnonymity Gateway - privacy protection tool that conceals IP address preventing your surfing habits and your internet activity form being tracked by websites or Internet Service Providers
    UAnonymizer Total Net ShieldAnonTns.exeAnonymizer Total Net Shield - ID protection and privacy software
    UANONYMIZER_SPYWAREKILLERSpyWareKiller.exeAnonymizer Spyware Killer - now Anti-Spyware
    UANONYMIZER_SPYWAREKILLERAnonAntiSpyware.exeAnonymizer Spyware Killer - now Anti-Spyware
    UAnother Internet Explorer Popup Killeraiepk2.exeAnother IE Popup Killer - pop-up stopper
    Xansjava[path to worm]Added by the RANDON-AN WORM!
    XAnskyaPYSKY.NET.exeAdded by the DLOADER-MW TROJAN!
    XAnswer ProblemdSAFsqs.exeAdded by the SDBOT-SC WORM!
    UAnswerToolAnswerTool.exeAnswerTool - save your E-mail replies in AnswerTool, then reuse them again and again
    XAntiIsass.exeAdded by the BROPIA.K WORM!
    XAnti Spam Servicespamsvc.exeAdded by the MYTOB-BK WORM!
    NAnti-Blaxx ManagerAnti-Blaxx.exeAnti-Blaxx - bypass blacklistings from different copy protections bypassing methods like virtual CD or DVD drives
    UAnti-keylogger checkantikey.exeAnti-keylogger - protects against keylogger programs monitoring your keystrokes
    UAnti-Trojan-WatchATWatch.exeAnti-Trojan Watch - trojan detector
    XAnti-Virusvpms.exeAdded by a variant of the SLAPER TROJAN!
    XAnti-Virus[random filename].exeAdded by the CAPROBAD-A TROJAN!
    XAnti-Virus Product Sync[unprintable character][3 characters]log.exeAdded by the KEDEBE.D WORM!
    XAnti-Virus Update Scheduler[path to trojan]Added by the SPAMMIT-A TROJAN!
    XAnti-Virus Update Schedulerwinsp3.exeMalware - detected by Kaspersky as the AGENT.FP TROJAN!
    XAnti-Virus Update Scheduler V1.39.12R[path to trojan]Added by the HEPLANE or STAPREW.B TROJANS! - different filenames have been spotted; examples: msvc.exe, kaspersky.exe, nrton.exe, wins.exe, gah32.exe, 1.tmp, syste.exe, alg.exe, socks.exe, winxpsp2.exe, tek9.exe, sks.exe, hihi.exe, s.exe, xps2.exe, dns2.exe, ikav32.exe and more...
    XAntiClickerSVCHST32.EXEAdded by the CBH TROJAN!
    Uantidialer.co.ukDialer_Watcher.exeDialer_Watcher is an application that allows you to detect dialers on your computer
    Xantihostahr.exeAdded by the BANCBAN-QJ TROJAN!
    UAntiPopUpAntiPopUp.exeAntiPopUp for IE - pop-up stopper
    XAntiSpyKit *.*AntiSpyKit *.*.exeEAdwareKiller spyware remover, where *.* represents the version number - not recommended, see here
    XAntispyStormAntispyStorm.exeAntiSpyStorm misleading security software - not recommended, see here
    XAntiSpywareAntispyware.exeAntiSpywareApp spyware remover - not recommended, see here
    XAntiSpywareBotAntiSpywareBot.exeAntiSpywareBot spyware remover - not recommended, see here
    XAntiSpywareMasterasm.exeAntiSpywareMaster spyware remover - not recommended, see here
    XAntiSpywareShieldAntiSpywareShield.exeAntiSpywareShield spyware remover - not recommended, see here
    XAntiVerminserAntiVerminser.exeAntiVerminser spyware remover - not recommended, see here
    Xantiviirusantiviirus.exeAdded by a variant of the AGENT.KEU TROJAN!
    XAntivirsvchst.exeAdded by the RAGRUK-A TROJAN!
    XAntiVirscvhost.exeAdded by the AGENT-DSF TROJAN!
    XAntiVirwinlog.exeAdded by the IRCBOT-TJ TROJAN!
    YAntiVir XPAVwin.exeAntiVir? PersonalEdition Classic - antivirus
    XAntiVirGear *.*AntiVirGear *.*.exeAntiVirGear misleading security software, where *.* represents the version number - not recommended, see here
    XAntivirusav.exeAdded by the SINKIN TROJAN! Resets IE start page to realphx.com
    XAntivirusmaja.exeAdded by the NETSKY.H WORM!
    XAntivirusiexpl0res.exeAdded by an unidentified WORM or TROJAN!
    XAntiViruskaspery.exeAdded by a variant of the RBOT WORM!
    XAntiVirusAntiVirus.exeAdded by the BANKER-EHB TROJAN!
    XAntivirus Installer[path to trojan]Added by the BADGENT-A TROJAN!
    XAntiVirus Processvirprot.exeAdded by a variant of the SDBOT WORM!
    XAntivirus Protection Servicesccapp2.exeAdded by the RBOT.EXI WORM!
    XAntiVirus Updateupdates.exeAdded by the RBOT-JF WORM!
    XAntiVirus Updateantivirus.exeAdded by the RBOT-IF WORM!
    XAntivirus-GoldenAntivirus-Golden.exeAntivirus-Golden misleading security software - not recommended, see here
    Xantivirus32antivirus.exeAdded by the SPYBOT.KAI WORM!
    XAntivirusGoldAntivirusGold.exeAntivirusGold malware
    XAntiVirusProAntiVirusPro.exeAntiVirusPro misleading security software - not recommended, see here
    XAntiVirusProMFCAntivirus Pro.exeAntiVirusPro misleading security software - not recommended, see here
    ?AntiVirusProtectionqumk.exe??
    XAntiVituSBase.exeAdded by the BAS.A WORM!
    Xantiwareelite***32.exe [*** = random char]Added by the DLOADER-HW TROJAN!
    UAntiWindowsMessengerAntiMsMsg.exeAnti-Windows_Messenger is a small application that prevents Windows Messenger from remaining resident in memory
    Xanti_trojanti_troj.exeAdded by the LODEAR.D TROJAN!
    YAnVirAnVir.exeAnVir Task Manager - protects computer against viruses and manages running processes and startup files
    YAnVir Task ManagerAnVir.exeAnVir Task Manager - protects computer against viruses and manages running processes and startup files
    Uanvshellanvshell.exeSystem Tray tool for ASUS video cards. If disabled you lose all the ASUS specific video card options in Control Panel -> Display Properties -> Advanced as well as the System Tray shortcuts toolbar
    UAny To-Do Listanytodo.exeAny To-Do List "the ultimate software solution to keep yourself organized and reminded"
    ?anycom bluetoothftflauncher.exeAssociated with an Anycom bluetooth wireless card. What does it do and is it required?
    UAnyDVDAnyDVD.exeAnyDVD - descrambles DVD-Movies automatically in the background and the DVD appears unprotected and region code free. Also removes prohibited operations from the DVD such as skipping adverts - hence the "U" recommendation
    NAO TrayAOTray.ExeSystem Tray application for AOpen soundcards. Can be run manually via Start -> Settings -> Control Panel
    Yaolavp.exeAOL's Active Virus Shield (by Kaspersky) - found in an AOLActive Virus Shield sub-directory
    XAOL 9.0 OptimizedAOLClient.exeAdded by the SPYBOTER.A TROJAN!
    UAOL Broadband Check-Upmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". The AOL Self Support Tool is required to run with the Help and Support program. If you uncheck AOL and and then run Help and Support it will add another AOL entry in the startup menu. If you remove this software in "add/remove programs" some help menus in help and support will not be available. You decide
    NAOL Companioncompanion.exePart of the AOL Connection Suite and installs an icon on the system tray offering easy access to AOL's additional utilities and functions. This program is a non-essential process, and is installed for ease of use
    XAol Configuration Loaderaimsng.exeAdded by the SDBOT-XE WORM!
    ?AOL Fast StartAOL.exeAOL ISP software related. What does it do and is it required?
    XAOL Instant Messangeraim.exeAdded by the SDBOT-YT WORM! Note - this is not the popular AOL Instant Messenger utility
    XAOL Instant Messengaraol.exeAdded by the AGOBOT-FN WORM!
    ?AOL Instant MessengerAlM.EXEThat is an L between the A and M, the start up location is wrong for AIM. What does this relate to?
    XAol Instant Messengeraolmsg.exeAdded by the KELVIR.AL WORM!
    XAOL Instant Messengeraimsgr.exeAdded by the IRCBOT.N TROJAN!
    XAOL Instant Messenger 7.213aim9283.exeAdded by the SDBOT-ZF WORM!
    XAol Instant Messenger Fixaolfix.exeAdded by the SDBOT-ABJ WORM!
    XAOL Messenger[random filename]Added by an unidentified VIRUS, WORM or TROJAN!
    XAOL Messengeraolmsngr.exeAdded by the SDBOT-JF WORM!
    XAOL Messenger OptimizedAOLOpt.exeAdded by the AOLOPT TROJAN!
    XAOL Services Hostsaolserviceshosts.exeAdded by an unidentified WORM or TROJAN!
    UAOL Spyware ProtectionAOLSP Scheduler.exeAOL's spyware protection program
    UAOL TopSpeedMonitoraoltsmon.exeAOL's TopSpeed web acceleration technology supposedly helps to make web browsing faster. Most important for those users who still access AOL via dial-up
    YAolAcsDaemon1Acsd.exeAOL Connectivity Service - starts an automatic function that restores the connection should you lose it while online. Negates having to go through the procedure of signing back on manually
    YAolAcsDaemon1AOLACSD.EXEAOL Connectivity Service - starts an automatic function that restores the connection should you lose it while online. Negates having to go through the procedure of signing back on manually
    ?AOLCCACCAgnt.exeAOL ISP software related, file located in a "AOL Computer Check-Up" folder. What does it do and is it required?
    XAolConconfig.comAdded by the TAPLAK WORM!
    NAOLDialerAOLDial.exeAOL ISP software dialer - can be activated through a desktop shortcut
    NAolFixAolFix.exeRun on Gateway Astra computers, and maybe a few others. Designed to repair a bad registry key in Gateway computers that would not allow AOL  to run correctly. Not seen much any more and should only run once
    XAOLRegKey32AOREGSVR512.EXEUnidentified malware - see here
    ?AOLSAVAOLAgent.exeAOL ISP related. What does it do and is it required?
    XAOLStartAOLStart.exeAdded by the KRAIMER.12 TROJAN!
    Xaolupdater.exeaolupdater.exeAdded by a variant of the IRCBOT TROJAN!
    XAornumaornum.exeInstalled along with iWon Prize Machine. Based upon their privacy statement this can be regarded as spyware
    NAOTrayAOTray.ExeSystem Tray application for AOpen soundcards. Can be run manually via Start -> Settings -> Control Panel
    Xaoueisysrtmvs.exeChivio dialer
    YAPC UPS StatusDisplay.exeAPC PowerChute Personal Edition status icon
    UAPC_SERVICEmainserv.exePowerChute? Personal Edition - "safe system shutdown software with sophisticated power management functions"
    Yapc_trayapc_tray.exePart of the APC UPS software loaded with the BACK-UPS CS 350 unit. Required to monitor the APC unit in case of power failure
    XAPD123APD123.exePacerD Media/Pacimedia.com adware
    XApi**.exe [* = random char]Api**.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
    XApi**32.exe [* = random char]Api**32.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
    XAPI32api32.exeAdded by the IRCBOT-B TROJAN!
    XAPIClasslexplore_.exeAdded by the MSNOPT-A TROJAN!
    XAPIMonapimonx.exeAdded by the TIBSER.A downloader TROJAN!
    XAPIMonwinapix.exeAdded by a variant of the TIBSER.A downloader TROJAN!
    XAPIMonmsreg.exeAdded by the DROPPER.Z TROJAN!
    Xapisvc.exeapisvc.exeAdded by a variant of the LAMEBOT TROJAN!
    UAPLAPL.exeSage Software's ACT! The application pre-loader (apl.exe) is a self contained executable that pre-loads the necessary .NET framework and ACT! 2005 assemblies. This pre-loading of assemblies enhances ACT! startup, view load and dialog load times in some areas of the application
    ?Apmsrv9xAPMSRV9X.EXEIntel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?
    UApointApoint.exeTouchpad software for laptop PC's. For instance it is found on the Panasonic and Sony Vaio machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work
    XApp**32.exe [* = random char]App**32.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
    XApp.EXEName[path to worm].exeAdded by the BODIRU WORM!
    UAppconvAppCon.exeVital Application Console - part of POS-partner 2000 point-of-sale software from Vital. This is the taskbar icon and is enabled at startup by the "Auto-start when OS starts" option. Required for a connection to be established
    Xappconnappconn.exeAdded by the CARGAO WORM!
    UAppExtenderAppExtCB.exeLoads the Confimax add-in for popular E-mail programs to confirm E-mails have been sent and received
    Xappis.exeappis.exeAdded by the AGENT-BC TROJAN!
    XAppletINITINITIATE.EXEAdded by the AGOBOT.XV TROJAN!
    YApplicationmdmsetsp.exeAztech Labs modem driver
    XApplication Adapterabvsvc.exeAdded by the CHECKOUT WORM! See here
    UApplication ExplorerNaldesk.exeNovell Zenworks Application Explorer Executable. "For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) will be run via the user's login script on each successful login. ZENworks is used to periodically deliver software updates and is also used to install the remote management components."
    UApplication ExplorerNalView.exeApplication Explorer - file manager type access to Novell Application Launcher for installing and updating network residing applications
    UApplication LauncherApplication Launcher.exeApplication launcher from the Sony Ericsson PC Suite for their mobile phones
    XApplication Layer Browserabgsvc.exeAdded by the ULPM.FX TROJAN!
    XApplication Layer Browserapnsvc.exeAdded by the CHECKOUT WORM! See here
    XApplication Layer Gateway Servicealgs.exeAdded by the LINKBOT.M WORM!
    XApplication Layer Scheduleragtsvc.exeDetected by PCTools as the IRCBOT.BJJ TROJAN! See here
    XApplication Layer Servicesavrsvc.exeDetected by PCTools as the IRCBOT.BJM TROJAN! See here
    XApplication Manageracnsvc.exeAdded by a variant of the IRCBOT TROJAN!
    XApplicationProtocolRunsmsbvl32.exeAdded by the IRCBOT-CX TROJAN!
    UAppPlusAppPlus.exeAppPlus - "menu bar or tray launcher that docks to your desktop, floats or sits in your System Tray. Create graphic/text-based buttons that launch any number of programs, Websites, e-mail addresses or folders (which open in the AppPlus Menu System)"
    YApvxdAPVXDWIN.EXEPart of Panda Antivirus. Required to enable permanent virus protection
    YApvxdwinAPVXDWIN.EXEPart of Panda Antivirus. Required to enable permanent virus protection
    UAPVXDWINClShield.exe"Panda ClientShield with TruPrevent is designed for companies that want the best protection for their workstations. It protects against viruses and other known and unknown threats including spam, spyware, dangerous or time-wasting content, phishing scams, hackers and intruders"
    YApwheelApwheel.exeWheel support for an Alps mouse 
    Xapyginapyginsimenu.exeAdded by the SDBOT.BTR WORM!
    UAQ3HelperStartUpAQ3HEL~1.EXEScreenScenes "Aquatica Water Worlds" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here
    Xaqadcup.exeaqadcup.exeAdded by the AGENT.BG WORM!
    YAqua DockAqua Dock.exeAqua Dock - "free program that allows you to have an ?OS X? style, nice animated launchbar / taskbar on your screen that reacts to your mouse when you mouse over it. Users can customize the look of each item on the dock and set various animation options for when the mouse is over an item on the dock. It is very easy to configure"
    XAqujyjax[path to file]Added by the RANCK-CQ TROJAN!
    XAqujyjaxaqujyjax.exeAdded by the SDBOT-YC WORM!
    Xara-key[random filename]Added by the ANTINNY WORM!
    Xarcaderockstararcaderockstar32.exeArcade Rockstar (now Gamevance) - free arcade games and prize tournaments. The program itself is clean, but the TOS and privacy statement say that you agree to allow the program to track/report your surfing and put popup advertising on your computer
    XArchivearchive.exeAdware - detected by Kaspersky as the CENTIM.A TROJAN!
    XARCHIVE CONTROLfixupdattr.exeAdded by the MYTOB.GU WORM!
    NARCSolo RecoveryN/ABackup software by Computer Associates - no longer supported
    UArdamax Keyloggerakl.exeArdakey B keystroke logger/monitoring program - remove unless you installed it yourself!
    Naresares.exe"Ares is a free open source file sharing program that enables users to share any digital file including images, audio, video, software, documents, etc"
    NaresliteAresLite.exe"Ares is a free open source file sharing program that enables users to share any digital file including images, audio, video, software, documents, etc"
    UArgentum Backupab.exeArgentum Backup - a small backup program that lets you easily back up your documents and folders
    XAritimaaritima.exeAdded by the ARITIM WORM!
    NARMOR2NETArmor2net.exeRelated to Armor2net personal firewall (possibly contains or is related to an anti-spyware product known as ArmorWall, which is a spyware remover - not recommended, see here
    Xaromisaromis.exeAdded by the NUWAR.JQ WORM!
    NAROReminderaro.exeAdvanced Registry Optimizer - "scan, identify, clean and repair errors in your Windows registry with a single click". Reminder that states that you are in trial mode
    NARPWRMSGARPWRMSG.EXERelated to HP and Compaq Desktop PCs. Read this article
    UArteraarteraui.exeArtera Turbo Internet Accelerator - "surf faster, boost download speed". Only required if you find it helps improve your performance
    ?AS00 Gear511Gear511.exeSoftware for Netgear wireless network cards. Unknown whether it is required for the wireless card to run but does not seem to be a resource hog. Not required for laptop to run if the wireless network card will not be used. Is it at all required?
    NAS00_Gear511Gear511.exeNetgear wireless LAN configuration utility
    UAS00_WN511BWN511B.exeNetgear RangeMax NEXT wireless adapter configuration utility
    ?AS00_WPN511WPN511.exeNetgearRev MFC Application - software for Netgear wireless network cards - what does it do and is it required in startup?
    XASDPLUGINdsldbaccess.exeAsdPlug premium rate adult content dialer variant
    XASDPLUGINcanada.exeAsdPlug premium rate adult content dialer variant
    XASDPLUGINfrance.exeAsdPlug premium rate adult content dialer variant
    XASDPLUGINfullgames.exeAsdPlug premium rate adult content dialer variant
    XASDPLUGIN100171be.exeAsdPlug premium rate adult content dialer variant
    XASDPLUGIN100176br.exeAsdPlug premium rate adult content dialer variant
    XASDPLUGINadult1.exeAsdPlug premium rate adult content dialer variant
    XASDPLUGINAustria.exeAsdPlug premium rate adult content dialer variant
    XASDPLUGINbelgium nm.exeAsdPlug premium rate adult content dialer variant
    XASDPLUGINczech.exeAsdPlug premium rate adult content dialer variant
    XASDPLUGINdbaccess.exeAsdPlug premium rate adult content dialer variant
    XASDPLUGINdslgeaccess.exeAsdPlug premium rate adult content dialer variant
    XASDPLUGINFinland.exeAsdPlug premium rate adult content dialer variant
    XASDPLUGINgeaccess.exeAsdPlug premium rate adult content dialer variant
    XASDPLUGINmexico.exeAsdPlug premium rate adult content dialer variant
    XASDPLUGINnetherlands.exeAsdPlug premium rate adult content dialer variant
    XASDPLUGINturkey.exeAsdPlug premium rate adult content dialer variant
    XASDPLUGINuk nm.exeAsdPlug premium rate adult content dialer variant
    XASDPLUGINXadult1.exeAsdPlug premium rate adult content dialer variant
    XASDPLUGINtemp532.exeAsdPlug premium rate adult content dialer variant
    Xasdsaxcxz13dasxcsx13.exeAdded by the LEGMIR-ARF TROJAN!
    Xasdxxwinrpc32.exeAdded by the AGOBOT.VO WORM!
    NASE SchedulerASE Scheduler.exeAluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here and here
    YAshampoo FireWallFireWall.exeAshampoo FireWall Free version
    YAshampoo FireWall PROFireWall.exeAshampoo FireWall PRO version
    UAshampoo PopUpBlockerPopUpKiller.exeAshampoo popup blocker, part of Magical Security (was Privacy Protector Plus)
    YashAvastashAvast.exePart of Avast antivirus
    XASHLTAshlt.exeAshlt adware
    YashMaiSvashmaisv.exePart of Avast! anti-virus software - E-mail scanner
    XAsicfcicfca.exeAdded by the AGENT.AAJE WORM!
    UAsioRegregsvr32.exe ctasio.dllASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality
    UAsioThk32Regrregsvr32.exe ctasio.dllASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality
    UASKrundll32.exe [path] ASK.dll rdlStealth Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
    XaslAslru.exeAdded by the BANCOS-CU TROJAN!
    UASMASMonitor.exeActive Security Monitor from AOL - helps you determine how vulnerable your PC is to computer viruses, spyware and other dangers and learn what steps you can take to improve your protection
    UAsmw Soft Popups Burnerpopups burner.exePopup blocker, part of Asmw Soft PC Optimizer
    Xasnconsolemsasn.exeAdded by the RBOT.EVU TROJAN!
    XASocksrvSocksA.exeAdded by the VB.CBW WORM!
    Xasp-srvcasp-srvc.exeAdded by the AGOBOT-KE WORM!
    XASP.NET State Servicecsrss.exeAdded by the DLOADER-QI TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
    XASP.NET State Servicecrsass.exeAdded by the BANLOAD-M TROJAN!
    XASP.NET State Serviceservicos..exeAdded by the DADOBRA-I TROJAN!
    Nasp4trayasp4tray.exeSystem Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
    YAspireTimeMachineacertmb.exeSystem recovery software supplied with some Acer notebook PCs. Similar to GoBack and the restore program in WinXP, allowing you to restore a PC back to a working state with minimal re-entry
    Xasrupdate.exeasrupdate.exeAdded by the VB.ATZ TROJAN!
    XassistseASSISTSE.EXECnsMin (Chinese Keywords) hijacker related
    XASTASTAdded by the TROJANDOWNLOADER.WIN32.VB.AH VIRUS!
    XASTASTAdded by the VB.AH TROJAN!
    XASTAST.exeAutoStarter parasite
    UASTARTastart.exeASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
    XAStartAStartAdded by the VB.AH TROJAN!
    NasTrayAstray.exeVoyetra Audio Station - part of Voyetra's Ultimate MP3 & CD Manager. MP3 and digital music jukebox/organizer
    NAstroAstro.exeChecks for updates to Quicken on a system reboot
    NASUS Live UpdateALU.exeASUS Live Update utility for their motherboards
    NASUS ProbeAsusProb.exeASUS video card fan/thermal monitor - only required if you overclock your card or live in a hot area
    UASUS SmartDoctorVGAProbe.exeASUS video card fan/thermal monitor
    UASUS TweakEnableastart.exeRestores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
    NASUSKeyV38SHELL.EXESystem tray Icon for quickly changing video modes
    UasustweakenableATweak.exeAsus tweaking utility - for fine tuning the settings of your ASUS display card
    NASWDPASWDP.exeMLS Pulse - real estate software. Keeps the home buyer/seller continually informed on the status of his/her local/regional real estate market
    XASWnkaswnk.exeAdult content dialler
    UAT-WatchATWatch.exeAnti-Trojan Watch - trojan detector
    Xatapidrvatapidrv.exeAdded by the AGOBOT-SL WORM!
    Uatchkatchk.exeAMT Status Message from Intel. Users can manage this, read the article. See here for more information on Intel AMT
    UAthanAthan.exeAthan - an application that calculates and reminds the five daily Islamic prayer times for anywhere in the world
    XATI Active Graphics Card Monitoratievx.exeAdded by the IRCBOT-TL WORM!
    XATI AS Filtermsnse.exeAdded by the RBOT-CCY WORM! Note - modifies the HOSTS file by appending numerous lines, preventing access to the virus cleaning websites
    NATI CATALYST System TrayCLI.exe SystemTraySystem Tray access to ATI's CATALYST? CONTROL CENTER. Note that this has "SystemTray" appended to CLI.exe in the "Command" column of MSCONFIG. Not required to run the control center - which is available via a right-click on the desktop
    NATI DeviceDetectATIDtct.EXEUtility meant for future use of the ATI TV WONDER USB 2.0 video driver and can be disabled
    XATI DisplayATIDisplay.exeAdded by the BDOOR-AFH TROJAN!
    XATI Display Driveratixd.exeAdded by the RBOT-FOV WORM!
    XAti Display Settingsatividx.exeAdded by the RBOT-GAS WORM!
    NATI GART Set-up UtilityAtigart.exeProgram that checks the motherboard chipset and determines which GART driver bundle to install on ATI video cards. If you have one, once installed it shouldn't be needed
    UATI Launchpadlaunchpd.exeConvenient way to start all your Multimedia Center applications (DVD, Video CD, CD Audio, File Player). You can right-click LaunchPad, and uncheck Load on Startup in the menu
    XATI Rage3d ProAtiRage4dPro.exeAdded by the AGOBOT-OG WORM!
    YATI Remote ControlATIRW.exeDriver for the ATI REMOTE WONDER? RF remote control for ATI's All-In-Wonder graphic cards and other products. Required if you use it
    YATI Remote ControlATIX10.exeATI Remote Wonder? - PC wireless remote control driver. Required if you use it
    NATI SchedulerAtisched.exeComponent that remains resident in memory and automatically launches the ATI VIDEO PLAYER at a user selected time and date. Delete the shortcut in the Start -> Programs -> Startup folder as well. Functions could re-enable the program to load at start-up and re-introduce the shortcut. Try it and see
    NATI Task ApplicationAtitkad.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
    NATI Task Application (Atikey)Atitask.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
    XATI Technology Startuptechstart.exeAdded by the RBOT-AEU WORM!
    XATI Video Driver Controlatigfx.exeAdded by the RBOT-FWL WORM!
    XATI Video Driver Controlbtorrent.exeAdded by a variant of the IRCBOT TROJAN!
    XATI Video Driver Controls[path to worm]Added by the SDBOT-DDS WORM!
    XATI VIDEO REGKEYati2vid.exeAdded by the SDBOT.UR WORM!
    ?Ati2cwxxAti2cwxx.exeFor some ATI video cards. Probably used to access features and may not be required - for example the ATI Radeon works fine without it 
    XAti2evxxAti2evxx.comAdded by the BACKDOOR-CPC TROJAN!
    Xati2f104ati2f104.exeAdded by the DLOADR-BBW TROJAN!
    UAti2mdxxAti2mdxx.exeSystem Tray icon to access ATI graphics card settings and the Hydravision Desktop Manager
    NATICCCcli.exe runtimeATI's CATALYST? CONTROL CENTER. Required if you want to change graphics settings on a regular basis but you must have internet access and Microsoft's .NET framework installed. Note that this has "runtime" appended to cli.exe in the "Command" column of MSCONFIG. Recommend that start the program manually via Start -> Programs -> ATI Catalyst Control Center -> Advanced -> Restart Runtime as it can casue problems when starting Windows
    NATICCCCLIStart.exePuts the ATI Catalyst? Control Center Icon/Shortcut on the System Tray - available via Start -> Programs
    Xaticpaxx.exeaticpaxx.exeAdded by the RBOT-XP WORM!
    UAtiCwdAtiCwd.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
    UAtiCwdAtiCwd32.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
    UAtiCwdAti2cwad.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
    UAtiCwd32AtiCwd.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
    UAtiCwd32AtiCwd32.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
    UAtiCwd32Ati2cwad.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
    XAtiDisplayDrvatidrvxx.exeAdded by the RBOT-VZ WORM!
    XatidriverreaIplayer.exeAdded by the WARPIGS-E WORM! Note the uppercase "I" in the filename, rather than a lower case "L"
    NAtiKeyAtiKey32.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
    ?AtiKeyatiptkad.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
    NAtikeyAtitask.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
    UATIMACEMACE.exeATI Technologies Control Centre - installed alongside ATI graphics hardware and provides additional configuration options for these devices in the Managed Access to Catalyst Environment (MACE) component
    UATIModeChangeAti2mdxx.exeSystem Tray icon to access ATI graphics card settings and the Hydravision Desktop Manager
    XAtiPanelatip.exeAdded by the TACTSLAY.U TROJAN!
    Xatipatxxatipatxx.exeAdded by the SMALL-ED TROJAN!
    UATIPOLABati2evxx.exeATI External Event Utility EXE Module. This task can comsume lots of CPU resournces  on some computers, but it can help with graphics card problems. Leave enabled unless it consumes too many CPU resources
    UATIPOLABati2evae.exeATI Polling Program - part of the ATI graphics driver e.g. on some Fujitsu-Siemens Notebooks
    UATIPOLLati2evxx.exeATI External Event Utility EXE Module. This task can comsume lots of CPU resournces  on some computers, but it can help with graphics card problems. Leave enabled unless it consumes too many CPU resources
    UAtiPTAAti2ptxx.exeControl panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
    UAtiPTAAtiptaxx.exeControl panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
    UAtiPTAAAAti2ptxx.exeControl panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
    UAtiPTAAAAtiptaxx.exeControl panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
    UatiptaxxAti2ptxx.exeControl panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
    UatiptaxxAtiptaxx.exeControl panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
    Xatiptextatiptext.exeAdded by the COSIAM-A TROJAN!
    UAtiQiPclAtiQiPcl.exeUsed for hardware DVD decoding on ATI video cards supporting this feature. Not required unless you regularly play DVD's
    UATISmartati2s9ag.exeATI's "SMARTGART", which is included with the "Catalyst" drivers. When the system boots, it runs a couple of bus tests & tries to apply the most stable settings
    UAtiSoundcsrss.exeWinSpy surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the "ComRoot" subfolder
    Xatisrc2windfind.exeAdded by the WINDFIND-A TROJAN!
    XATITechActive.exeAdded by the ROAMER-A TROJAN!
    Uatitrayatitray.exeATI Tray Tools - allows quick access to ATI graphics card settings
    UAtiTrayToolsatitray.exeATI Tray Tools - allows quick access to ATI graphics card settings
    XatiupdateATIUPDATE5.EXEAdded by the DEBESKI.A TROJAN!
    Xatiupdatemsshed32.exeAdded by the DELF.EP downloader TROJAN!
    XATIUpdateratiupdxx.exeAdded by the RBOT-ABX WORM!
    XAtiupdplatiupdpl.exeAdded by the SMALL.AOS TROJAN!
    Xativopenativopen.exePremium rate adult content dialler
    YATIX10atix10.exeATI Remote Wonder? - PC wireless remote control driver. Required if you use it
    ?ATKMEDIADMEDIA.EXEATK Media utility for ASUS laptops - what does it do and is it required?
    XAtl**.exe [* = random char]Atl**.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
    XAtl**32.exe [* = random char]Atl**32.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
    XATM Controladpn.exeAdded by the MMS.A WORM!
    NATnotesatnotes.exeLoads the ATnotes program for virtual sticky notes for your desktop. Available via Start -> Programs
    UAtomic Time SynchronizerTimeSync.exeTimeSync - lets you synchronize your computer's clock with any internet atomic clock
    XAtomic-x27Atomic-x27.exeAdded by the KATOMIK-A WORM!
    XAtomic-x27CAtomicpartC.exeAdded by the KATOMIK-A WORM!
    UAtomic.exeAtomic.exeAtomic Clock Sync - synchronizes your computer's time with the NIST time server
    NAtomicaatomica.exeAtomica runs from the System Tray and allows the user to find out more about a word or phrase on any screen by pointing at it with the mouse and clicking button one while holding down the Alt key
    UAtomicTimeATOMICTIME.EXEAtomicTime - utility that synchronizes your PC clock to an atomic clock
    UAtrackatrack.exeNew feature of Norton Internet Security (NIS) and Norton Personal Firewall (NPF) 3.0 is the Alert Tracker, an instant notification feature. The Alert Tracker displays information about events as they happen. This way, when a rule has been triggered or an access to the Internet made, you know about it immediately rather than finding out about it when you check your logs or notice that the NIS icon indicates a security alert
    UAtrayAtray.exeActive Tray is a utility which lets you configure the system tray. You can also create your own tray icons
    UATSpoolerAppsTraka.exeDeskTopScout keystroke logger/monitoring program - remove unless you installed it yourself!
    UATTBroadbandUpdateSAUpdate.exeBig Brother from Quest Software. System and network monitor
    UATTRedUpdateAutoUpdate.exeAdditional item added to start-ups after AT&T took over the now bankrupt Excite@home high-speed internet service. Included for automatically downloading and installing updates. Leave it unless you plan to regularly run it to check for updates
    XAttuneClientEngineattune_ce.exeAveo Attune automated helpdesk software - adware/spyware
    XAttuneContentUpdaterattune_cu.exeAveo Attune automated helpdesk software - adware/spyware
    XAttuneDiscoveryattune_di.exeAveo Attune automated helpdesk software - adware/spyware
    XAttunelAttunel.exeAveo Attune automated helpdesk software - adware/spyware
    XAttuneSystrayattune_st.exeAveo Attune automated helpdesk software - adware/spyware
    NaTuneratuner.exeaTuner - tweak tool for GeForce based graphics cards
    Yatwtusbatwtusb.exeUSB interface for Aiptek Graphics Tablet (USB)
    XAtxBrwIexplor.exe"Pop Marketing" adware
    UauDealioAu.exeDealio Toolbar is a free shopping comparison toolbar that allows users to search for a wide range of consumer products
    UAU AgentAUagent.exeAu Agent from Zilab Software. Win2K/NT enhancement tool. Allows you to run applications under any security context without closing the whole logon session to process a new logon
    Xau.exeau.exeAdded by the BEAGLE.B WORM!
    YAUCBPNPaucbnpn.exeAdaptec USB CardBus Safe-Eject - driver for the Adaptec USB 2.0 CardBus which provides USB 2.0 ports for laptop users via a PCMCIA card slot
    XAucompatAucompat.exeAdded by the GEMA TROJAN!
    XAudcntraudcntr.exeAdded by the GEMA TROJAN!
    ?AudCtrlRunDll32 AudCtrl.dll, RCMonitorAudio control panel?
    Xaudi32audi32.exeAdded by the RANCK-FL TROJAN!
    XAUDIOSOUND.exeAdded by the PLOYB-A TROJAN!
    XAudio Device Managerwinfp.exeDetected by PCTools as the IRCBOT.BIV TROJAN! See here
    XAudio Device ManagerWinNT.exeAdded by the BANKER.BTG TROJAN!
    XAudio Device ManagerWNDXP.exeDetected by Kaspersky as the IRCBOT.AJL TROJAN! See here
    Xaudiocfg.exeaudiocfg.exeAdded by the VB.ATE WORM!
    XAudiocntlaudiocntl.exeAdded by a variant of the CRYPTER.C TROJAN!
    NAudioDeckADeck.exeADeck.exe is a system tray application for VIA's sound cards which offers quick access to a number of sound card related items
    XAudiodrvaudiodrv.exeAdded by the CRYPTER-C TROJAN!
    UAudioDrvEmulatorDLLML.exe AudDrvEm.dllRelated to Creative DLL Module Loader for the Sound Blaster X-Fi (and maybe others). This program is non-essential process to the running of the system, but should not be terminated unless suspected to be causing problems
    NAudioHQAhqtb.exeFor Creative Soundblaster Live! series soundcards. System tray application for SB Live! functions. Available via Start -> Programs
    XAudioHQaudiohq.exeAdded by the BANKER-EHK TROJAN!
    NAudioHQUAHQTBU.EXESystem Tray application installed with the drivers for Creative Labs SoundBlaster Live! Can be run from Start -> Programs
    Xaudioinfaudioinf.exeAdded by a variant of the CRYPTER.C TROJAN!
    Xaudlmne32dcmsxe.exeAdded by the MAILBOT-CF TROJAN!
    Xauloadplxmplprogsm.exeAdded by the SLAPER.K TROJAN!
    XAUNPS2RUNDLL32 AUNPS2.DLL, _Run@16AUNPS adware
    Xaupdsymcsvc.exeAdded by the ABWIZ.D TROJAN!
    Xaupdsysvcs.exeAdded by the ABWIZ.C TROJAN!
    Xaupdsywsvcs.exeAdded by the ORSE-M TROJAN!
    YAureal A3D Interactive Audiosa3dsrv.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
    YAureal A3D Interactive Audio InitA3dInit.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
    Xausvcausvc.exeAdded by the AUTOUPDER TROJAN!
    XAuth Starter Identstartauth.exeAdded by the RBOT-WP WORM!
    YAuthentic-ID Toolbarwintmr.exeSystem Tray access to Child Control parental control software by Salfield
    YAuthentic-ID Toolbarrundll32.exe [path] ToolbarATL.dll, LoadTrayIconAuthentic-ID Toolbar - website authentication utility. Warns you when a site is recognized for phishing or isn't authentic, for example
    Xauthzauthz.exeAdded by an unidentified VIRUS, WORM or TROJAN!
    Xautowin32.exeAdded by the SMALL!SD5 TROJAN!
    XAuto CD-ROM Startupcdaccess.exeAdded by the SPYBOT.BLA WORM!
    UAuto EPSON Stylus C45 Series on XE_S4I3T1.EXEEpson Status Monitor 3 for the Stylus C45 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus C48 Series on XE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus C60 Series on XE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus C62 Series on XE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus C82 Series on XE_S0HIC1.EXEEpson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus C84 Series on XE_S4I2D1.EXEEpson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus C87 Series on XE_FATIABL.EXEEpson Status Monitor 3 for the Stylus C87 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus CX3200 on XE_S10IC2.EXEEpson Status Monitor 3 for the Stylus CX3200 printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus CX3600 Series on XE_FATI9BE.EXEEpson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus CX3800 Series on XE_FATIACA.EXEEpson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus CX4200 Series on XE_FATIAEA.EXEEpson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status, checking ink levels, etc, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus CX4500 Series on XE_FATI9AP.EXEEpson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus CX5400 on XE_S4I2G1.EXEEpson Status Monitor 3 for the Stylus CX5400 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus CX6000 Series on XE_FATIBIA.EXEEpson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus CX6400 on XE_S4I2L1.EXEEpson Status Monitor 3 for the Stylus CX6400 printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus CX6600 Series on XE_FATI9EE.EXEEpson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus CX7800 Series on XE_FATIACA.EXEEpson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus D78 Series on XE_FATIBGE.EXEEpson Status Monitor 3 for the Stylus D78 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus D88 Series on XE_FATIABE.EXEEpson Status Monitor 3 for the Stylus D88 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus DX3800 Series on XE_FATIACE.EXEEpson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus DX4800 Series on XE_FATIADE.EXEEpson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus DX6000 Series on XE_FATIBIE.EXEEpson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus Photo R1800 on XE_FATI9LA.EXEEpson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus Photo R200 Series on XE_S4I2H1.EXEEpson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus Photo R200 Series on XE_S4I0H2.EXEEpson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus Photo R220 Series on XE_FATIAIE.EXEEpson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus Photo R260 Series on XE_FATIBNA.EXEEpson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus Photo R300 Series on XE_S4I2F1.EXEEpson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus Photo R320 Series on XE_FATI9FA.EXEEpson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus Photo RX420 Series on XE_FATI9CE.EXEEpson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus Photo RX500 on XE_S4I2K1.EXEEpson Status Monitor 3 for the Stylus Photo RX500 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus Photo RX600 on XE_S4I2M1.EXEEpson Status Monitor 3 for the Stylus Photo RX600 Series printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    UAuto EPSON Stylus Pro 7600 on XE_S10IC2.EXEEpson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status, checking ink levels, etc. "X" represents the computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc
    XAuto File System Conversion Utilityscricon.exeAdded by the SDBOT.EYB WORM!
    Xauto repair systemqualityx.exeAdded by an unidentified WORM or TROJAN - probably a SPYBOT variant
    UAuto SwitchTASKBAR.exeRelated to 2-port Bitronics AutoSwitch kit from Belkin
    NAuto T Barautotbar.exeIf you disable the HP VIEW toolbar in IE and rearrange the toolbars on a reboot they will be back as they were before if this is left enabled
    XAuto UpdatWindowsSys32.exeAdded by a variant of the FORBOT WORM!
    XAuto updatcrcss.exeAdded by the SDBOT.AAG WORM!
    XAuto UpdateAUP.exeAdded by an unididentified WORM or TROJAN!
    XAuto Updatedma.exeAdded by the RBOT-AVO WORM!
    XAuto Updatesvchost.exeAdded by the DUMARDI-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
    XAuto Updatessvchost.exeAdded by the CHEUKO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
    XAuto WinUpdatetaskmrg.exeAdded by the RBOT-AFA WORM!
    XAutoAdministratorSERVICES.EXEAdded by the PUNYA-A WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
    UAutobarautobar.exeConnect buttons on the keyboard for internet direct access, etc. on HP computers
    UAutoCAD Startup Acceleratoracstart16.exePreloads some libraries that are used by AutoCAD in order to make the software load faster
    Uautoclkautoclk.exeAutoclik is a Windows utility "that allows you to perform all mouse activity with absolutely no clicking"
    NAutoEAAhqrun.exeFor Creative Soundblaster Live! series soundcards. Specify for any audio application what audio preset to automatically associate with currently active speaker output. Available via AudioHQ
    XAUTOEXEAUTOEXE.exeAdded by the SEMAPI-A WORM!
    Xautoloadcftmon.exeDetected by Symantec as the SILLYFDC WORM! See here
    Xautoloadspooll.exeDetected by Symantec as the SILLYFDC WORM! See here
    Xautoloadwindowsupdate.exeDetected by Trend Micro as the POLYCRYP.DY TROJAN! See here
    XAutoloaderaproposclientApropos_Client_Loader.exeAproposMedia adware
    XAutoloaderaproposclientcxtpls_loader.exeAproposMedia adware
    XAutoLoaderEnvoloAutoUpdaterauto_update_loader.exeEnvolo/AproposMedia adware updater
    NAutoMate Task Service automate.exeTask scheduler for Unisyn Automate 4 task automation/macro running software. Available via a desktop shortcut or Start -> Programs
    UAutoMate5Am5HkWnd.exe"Automate is the Leading Software for Automation of front and back-office business processes.It provides all the tools necessary to completely automate business processes, regardless of their complexity"
    UAutoMate6AMEM.exeAutoMate 6 for automating repetitive tasks
    XAutomated Windows Updateswauclt.exeAdded by the GAOBOT.AJD WORM!
    XAutomatic Defrag Managerdefrag.exeAdded by the RBOT-AKE WORM!
    XAutomatic Media UpdateCACHE.RVDAdded by an unidentified WORM/TROJAN!
    XAutomatic Media UpdateHPLNT32.RVDAdded by an unidentified WORM/TROJAN!
    XAutomatic Microsoft Windows Updatersuchost.exeAdded by the RBOT-EQ WORM!
    XAutomatic Updatesalgs.exeAdded by the IRCBOT-AAM TROJAN!
    XAutomatic Windows UpdaterUpdate.exeAdded by the GAOBOT.AO WORM!
    NAutomatically launches the United Devices Agent when you start your computerUD.EXEThe United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start > Programs
    XAutopdateAutopdate.exeAdded by the RBOT-AGL WORM!
    NAUTOPROPREGPROP.EXE WMPADDIN.DLLBoth the files are in the MS Office/Bots/FP_WMP directory. Apparently, it registers the FrontPage WiMP extension
    XAUTOPROTECTUnavapq32.exeAdded by an unidentified WORM or TROJAN!
    Xautorepairdexs.exeAdded by a variant of the SDBOT WORM!
    UAutoroute SMTPAutoSmtp.exeAutoroute SMTP - "automatic switching between SMTP servers depending on what network you are currently working in." You need to have two Internet service providers
    Xautorunautorun.exeAdded by the AUTOM-B WORM!
    Xautorunsxs.exeAdded by the SMALLVBS-A WORM!
    Xautorunwinmain.exeAdded by a variant of the DLEF.CNS TROJAN!
    Xautorundemo[path to trojan]Added by the AGENT-FPX TROJAN!
    ?AutoShutdownpssvc.exeUtility to fix vCard Export in MS Outlook 2000 - although why are these together?
    UAutoSizerAUTOSIZER.EXEAutoSizer - utility that automatically maximizes windows when they're opened
    NAutoSpellautospel.exeAutoSpell - spell checker (version 6.*)
    NAutoSpell 5ASWATC32.EXEAutoSpell - spell checker
    UAutoSysautosys.exeWinguardian surveillance software. Uninstall this software unless you put it there yourself
    Nautotbarautotbar.exeIf you disable the HP VIEW toolbar in IE and rearrange the toolbars on a reboot they will be back as they were before if this is left enabled
    NAutoTKitAUTOTKIT.EXEOn HP PC's. Unclear what purpose it serves - but there's a known issue with Internet Explorer Toolbar settings not being saved with it enabled
    Nautoupdautoupd.exeRaxco Software Auto Update utility."Used to keep your software up-to-date"
    Xautoupdautoupd.exeAdded by an unidentified VIRUS, WORM or TROJAN! - found in a folder of the same name
    XautoupdateWINUP2DATE.DLL, SHStartUnidentified adware - detected by Panda antivirus as the CLICKER.CY TROJAN!
    Xautoupdaterundll32 DATADX.DLL, SHStartAdded by a variant of the QOOLOGIC TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "DATADX.DLL" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    Xautoupdaterundll32 SUPDATE.DLL, SHStartAdded by a variant of the QOOLOGIC TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "SUPDATE.DLL" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    XAutoUpdatesmss.exeAdded by a variant of the WINSPY.AA TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "debug64" subfolder of the Winnt or Windows folder
    XAutoupdate Servicekaka.exeAdded by the SYMPE-B TROJAN!
    XAutoUpdateraupdate.exeTinybar variant
    XAutoUpdaterAutoUpdate.exePeopleonPage foistware
    Xautoupdatev2[path to file]Added by the DROPPER-BM TROJAN!
    Xautoupdatev2autoupdatev2.exeDetected by Kaspersky as the AGENT.FQ TROJAN!
    XAutoVirusProtectionciscv.exeAdded by a variant of the RBOT WORM!
    Xauto__antiav__keyantiav_exe.exeAdded by the BAGLEDI-AA TROJAN!
    Xauto__hloader__keyhloader_exe.exeAdded by the BAGLE.AB TROJAN!
    Xaux.exeaux.exeAdded by the ZINS TROJAN!
    XauxAudioDeviceaux32.exeAdded by the AIZU WORM!
    NAUXXTRAYau30setp.exeSystem Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
    XAVUPDATE-28062004.exe[25 blank spaces].vbsAdded by the MIDFIN WORM!
    XAV Clientpatch31345.exeAdded by the MYDOOM.AD WORM!
    XAV Industrypatch31345.exeAdded by the MYDOOM.AD WORM!
    XAV UpDateUpdate.exeAdded by the FUROOT-A TROJAN!
    NAvaFindAvaFind.exeAvaFind file search utility
    XAVantivirusAvconsol.exeAdded by the MSNVB-D WORM!
    Xavasttroyan.exeAdded by the SMALL.CZ TROJAN!
    YAvast!ashserv.exePart of Avast! anti-virus software
    Yavast!ashDisp.exePart of Avast! anti-virus software
    Yavast! Web ScannerAshwebsv.exePart of Avast! anti-virus software
    YAvast32Astart32.exePart of Avast! anti-virus software
    Xavcavmon.exeAdded by an unidentified TROJAN!
    UAvconsoleEXEAvconsol.exeFrom McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Used to schedule regular scans. If you don't have scans scheduled you don't need it
    XAvengineAvengine.comAdded by the DELF.LJ TROJAN!
    XAveoAttuneatmdlusr.exeAveo Attune automated helpdesk software - adware/spyware
    UAVFX EngineStartFX.exeAdvanced Video FX - supported by a number of Creative Web Cameras. "Have more fun by adding a wide range of special effects and backgrounds to your video chat with Advanced Video FX"
    XAvGsvchost323.exeAdded by the RBOT-ZA WORM!
    YAVG Anti-Virus systemavgcc.exeAVG Anti-Virus 7.0 Control Center. Allows you to manage and control all AVG Anti-Virus components, settings and updates
    XAvg Antivirusicpldrvx.exeAdded by the BANKER.BYU TROJAN!
    XAVG Grisoft Updaterupdater.exeAdded by the AGOBOT-OT WORM!
    YAVG7_AMSVRAvgamsvr.exeAVG antivirus related
    YAVG7_CCAVGCC.exeAVG Anti-Virus 7.0 Control Center. Allows you to manage and control all AVG Anti-Virus components, settings and updates
    YAVG7_CCavgcc.exeAVG Anti-Virus 7.0 Control Center. Allows you to manage and control all AVG Anti-Virus components, settings and updates
    YAVG7_EMCAVGEMC.exeAVG Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses
    YAVG7_Runavgw.exeAVG Anti-Virus 7.0 related
    UAVG8_TRAYavgtray.exeSystem Tray access to AVG internet security software
    Yavgamsvr.exeAvgamsvr.exeAVG antivirus related
    Yavgcc32avgcc32.exeAVG anti-virus control center. Also enables scheduled tests, Outlook E-mail plug-in and automatic updates
    YAVGCtrlAVGCtrl.exePart of AntiVir? PersonalEdition Classic antivirus
    YavgfwsrvAVGFWSRV.EXEFirewall part of the AVG Plus Firewall Edition
    Yavgmsvr.exeavgmsvr.exeAVG Anti-Virus 7.0 related
    YAVGntAVGnt.exeAntiVir? PersonalEdition Classic antivirus. System Tray icon and control program
    YAvgserv9.exeAvgserv9.exeAVG antivirus background monitoring
    YAVGuardAVGuard.exeAntiVir? PersonalEdition Classic antivirus. Background task which scans files transparently
    YAVG_CCavgcc32.exeAVG anti-virus control center. Also enables scheduled tests, Outlook E-mail plug-in and automatic updates
    YAVG_EMCAVGEMC.exeAVG Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses
    YAVG_RegCleanerAVGREGCL.exeAVG Anti-Virus 7.0 Registry Cleaner - for checking the registry for virus additions and other security problems
    Xavidrvdrvsc.exeDetected by Kaspersky as the AGENT.PH TROJAN!
    XAvimgtAvimgt.exeAdded by the GEMA TROJAN!
    XAvimgt32Avimgt32.exeAdded by the GEMA TROJAN!
    YavinitAVINIT9X.EXECommand Antivirus related
    YAVK Mail CheckerAVKPop.exeeXtendia AVK AntiVirus email checker
    YAVKBarAVKBar.exeGData AntiVirusKit Anti-virus
    UAVKTrayAVKTray.exeSystem Tray access to AntiVirenKit InternetSecurity from G DATA Software AG
    YAvMaiSrvAvmaisrv.exePart of Avast! anti-virus software - E-mail scanner
    YAVMWlanClientwlangui.exeRelated to broadband products from avm.de
    Xavnortformatsys.exeAdded by the SERFLOG.A WORM!
    Xavnortmsmbw.exeAdded by the SERFLOG.A WORM!
    Xavnortserbw.exeAdded by the SERFLOG.A WORM!
    Yavpavp.exeKaspersky anti-virus and AOL's Active Virus Shield (by Kaspersky) - found in either a Kaspersky or AOL sub-directory
    XAVP[path to trojan]Added by the MUTBO-A TROJAN!
    Xavpavp.exeDetected by Kaspersky as the ALPHABET.B TROJAN!
    Xavpwin*.tmp.exe [* is a number]Added by a variant of the ALPHABET TROJAN!
    Xavpxar6000v7.exeDetected by Kaspersky as the ALPHABET.B TROJAN!
    XAVP-SEavp-32.exeAdded by the AGOBOT.FS WORM!
    Xavpaavpo.exeAdded by the LEGMIR-ARK TROJAN!
    Yavpccavpcc.exeKaspersky Labs anti-virus
    Yavpmavpm.exeKaspersky anti-virus
    XAvpMAvpM.exeAdded by the STARTPAGE-ID TROJAN! Note - this is not the popular Kaspersky antivirus and this file is located in the WINDOWSpchealthUploadLBConfig directory
    Xavpmsavpms.exeDetected by Kaspersky as the ONLINEGAMES.CPV TROJAN! See here
    XAvpravpr.exeAdded by the MYDOOM.AF WORM!
    XAVPSrvAVPSrv.exeAdded by the ONLINE-GEN TROJAN!
    Xavptask[path to trojan]Added by the NOFERE-G TROJAN!
    Xavptaskexpl0rer.exeAdded by the AGENT.JJO TROJAN!
    XAvptaskrund1132.exeAdded by the AGENT.PKZ TROJAN!
    XAvpWxWErcx.exeDetected by Kaspersky as a variant of the AGENT.A TROJAN!
    XAvril Lavigne - Muse[random filename]Added by the AVRIL-A WORM!
    YAVSCHED32AVSched32.exeAntiVir? PersonalEdition Classic - antivirus
    YAVSchedScanSCHSC9X.EXECommand Antivirus related
    XAvSerdsm.exeAdded by the SERFLOG.B WORM!
    XAvSermsmpatch.exeAdded by the SERFLOG.B WORM!
    XAvSersvosm.exeAdded by the SERFLOG.B WORM!
    XAvSersysup.exeAdded by the SERFLOG.B WORM!
    Xavserve.exeavserve.exeAdded by the SASSER WORM!
    Xavserve2.exeavserve2.exeAdded by the SASSER.B or SASSER.C WORMS!
    Xavserve3.exeavserve3.exeAdded by the SASSER.G WORM!
    UAVStation premiumAVStation agent.exeRelated to Samsung AV Station - instant playback of music, photos, videos
    Xavtapiavtapi.exeAdded by the AGENT.AM TROJAN! Note - example names include "XviD", "Winamp Remote", "Windows Media Player" and "Futuremark"
    NAvtrayAvtray.exeCommand Antivirus tray icon
    XAVupdate32 UpdateAVupdate32.exeAdded by the RBOT.CNI TROJAN!
    ?AVWLPSTAAVWLPSTA.exePRISM Status Tray Applet - but what is it for and is it required?
    YAVWUpd32AVWUPD32.EXEAntiVir? PersonalEdition Classic - updater
    Yavx communicatorxcommsur.exeAnti-virus part of BitDefender virus scanner/firewall
    YAvxliveavxlive.exeBullguard or BitDefender antivirus
    Yavxlniavxinit.exeAnti-virus part of BitDefender virus scanner/firewall
    ?Avxnews????
    UAwatchAwatch.exeDiagnosis tool that monitors DSL connections, installed alongside DSL drivers from AVM Fritz's range of modem products
    UAwaySchAwaySch.EXEPart of the IBM ThinkVantage Productivity Center. "The Away Manager application allows you preselect and run routine tasks to maintain your system's performance"
    Nawhost32awhost32.exePart of Symantec's pcAnywhere remote PC management software. Provides an automatic startup of the client PC in host mode in conjuction with a host-definition file, so system administrators can access the machine. Can cause a 10% reduction in speed and not recommended
    UAWMONAd-Watch.exePart of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system
    UAWMONAd-Monitor.exeF-Secure Anti-Spyware
    Uawpliteawplite.exeAllWallpapers Lite desktop wallpaper channger
    ?AWUSGSTAAWUSGSTA.exeReportedly related to a USB Wifi Adapter - is it required at startup?
    UawxDToolsawxDTools.dll, awxRegisterDllAwxDTools related - a Windows Shell-Extension for the Daemon-Tools. It extends the context-menu of ImageFiles supported by Daemon-Tools (i.e.: *.cue, *.iso, *.ccd ...)
    ?AxFilterRundll32 AXFILTER.DLL, Rundll32??
    XAXVenoreAXVenore.exeAdded by an unidentified TROJAN - see here
    UAzMixerSelAzMixerSel.exeRelated to Realtek_Azalia Mixer Selector
    Yazmodemazexe.exeAztech Labs modem driver
    ?a_vpdvpd.exeLocated in the IBMTOOLSVPD sub-directory. What does it do and is it required?
    NB'sCLiPBSCLIP.exeCD recording utility that comes with a lot of CDR/CDRW drives and isn't required
    Xb.exeb.exeAdded by the SDBOT.BND WORM!
    NB.Readerremin.exeBirthday Reminder 5.0 - as the name implies
    Xb3dBDEsecureinstall.exeB3d Projector foistware - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in the "System" directory. (3) Disable and ideally delete it from the registry. (4) Remove the "BDE" directory and all its contents
    Xb3dUpdateZupdate.exeAssociated with B3d Projector foistware - see here
    Ub9B9.exeFireTrust Benign - allows you to receive e-mail which is safe from viruses, worms, scripts, web bugs, privacy threats and other security risks, without affecting your e-mail. "Benign neutralizes or strips out the code that makes viruses, worms, scripts and other potentially harmful things run"
    Xb99msmm.exeClientMan parasite variant
    Xbabsvchst32.exeAdded by the AGENT.Q TROJAN!
    Xbabeierundll32 cnbabe.dll, dllstartupCommonName Toolbar spyware. To uninstall see here
    NBabylon ClientBabylon.exeBabylon-Pro is a powerful information tool that instantly provides relevant information, translations & conversions for any word or value you click on"
    NBabylon TranslatorBabylon.exe"Babylon-Pro is a powerful information tool that instantly provides relevant information, translations & conversions for any word or value you click on"
    XBack UpdatesUninstall.log.vbsAdded by the YPSAN.D WORM!
    UBack2zipBack2zip.exeBack2zip is a simple and elegant backup solution which uses the industry's most powerful ZIP and ZIP-64 technologies to constantly monitor your documents and make sure that they are always properly backed up
    XBackdoor.NuAgentagent.exeAdded by the AGENT-DP TROJAN!
    XBackground Intelligent Transfer Servicerundll32.exeAdded by the VB-ZD TROJAN! Note - this file is located in the C:Windowshelp folder, and is not to be confused with the legitimate rundll32.exe file!
    UBackgroundSwitcherbgswitch.exeOriginally included with Microsoft's XP PowerToys (but now withdrawn - see here, Background Switcher allows your desktop background to periodically change
    UBackgroundSwitcherBackgroundSwitcher.exeJohn?s Background Switcher (or JBS for short) periodically changes the background image on your computer (like every hour or every day) to something interesting
    NBackpack UDFbpudfmon.exeBackpack UDF packet writing software for Microssolutions' Back Pack external CD-RW drive. Similar to DirectCD. Run manually before insert an appropriately formatted CD-RW disk
    Xbackup[path to worm]Added by the AGOBOT-H WORM!
    XBackup Servicebackup.svcUnidentified adware
    UBackup4all OTB AgentB4AOTB.exe"Backup4all is an award-winning data backup software for Windows. This backup utility was designed to protect your valuable data from partial or total loss by automating backup tasks, password protecting and compressing it to save storage space"
    UBackupExecSchedulerbesch.exeVeritas "Back Up My PC" software
    ?BackupNotifybackupnotify.exeHP Digital Imaging related. What does it do and is it required?
    NBackWebbackweb.exeAutomatically detects an internet connection and downloads any available updates. Typical on Compaq and HP PC's but not restricted to those OEM's. Resource hog and often causes malfunctions. Available via Start -> Programs
    NBackworkBackwork.exeBackwork trojan detector
    UBACPI10bacpi10a.exeKnown as "PowerKey" - a minimalistic keyboard driver that allows power management keys on BTC keyboards to function properly in older OS's (i.e. Win95/98/NT4). Also adds an icon to the system tray
    NBacsTrayBacsTray.exeBroadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems
    XBADDATEBADDATE.EXEAdded by an unidentified VIRUS, WORM or TROJAN!
    XBagleAVcsrss.exeAdded by the NETSKY.AB WORM! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
    XBakraIEHost.EXEAdded by the MULTIDR-AH TROJAN!
    XbalSYSMONMS.EXEAdded by the FAKEALERT TROJAN!
    XBand-Aid[path to file]Added by the RANKY.O TROJAN!
    Ubandmonbandmon.exeRokario Bandwidth Monitor
    XBandookali.exeAdded by the EXEMAS-B TROJAN!
    UBandwidth Monitor ProBandwidth Monitor Pro.exeBandwidth Monitor Pro - utililty to track your current download/upload limit that may be set by your ISP
    UBanpopup by PratikBanpopup.exeBanpopup - popup killer
    Xbantoolie_ban.exeDetected as the VB.PO TROJAN!
    XBar Ding loltAnaliz.exeAdded by the RBOT-RP WORM!
    Xbargainsbargains.exeBargainBuddy foistware
    Xbargainsbargainbuddy.exeBargainBuddy foistware
    ?Bart Stationstation.sbrtRelated to PeoplePC ISP. May be a dialler for dial-up accounts?
    UBart StationPPCOLink.exeDialer for PeoplePC ISP
    XBarThemebartent32.exeAdded by the AGOBOT-UG WORM!
    NbascstrayBascsTray.exeBroadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems
    XBatsecure2.batAdded by the ZCREW.C TROJAN!
    NBatchreg1N/APart of the Windows System Recovery process. Added to the registry via Msbatch.inf. The existence of this key or process after the last reboot during installation indicates an unsuccessful installation, as that key should be deleted automatically. See here
    UBatInfExrundll32.exeDisplays battery status information on an IBM Thinkpad
    XBatSrvbatserv2.exeDetected by Kaspersky as the LOCKSY.M WORM!
    UBattery Scopebatmgr.exeMonitors battery levels on a notebook/laptop PC
    UBatteryBarbatterybar.exeBatteryBar - displays battery usage, and the current percentage of battery power left
    XBatzBackBatzBack.scrAdded by the BACKZAT WORM!
    UBAUSBBAUSB.exeBoston Acoustics Audio, USB driver
    Xbawindobawindo.exeAdded by the BEAGLE.AR or BEAGLE.AU WORMS!
    UBayMgrDockApp.exeHot-swappable drive management on laptops allowing you to change drives without closing down Windows. Only required if you frequently swap bay devices 
    UBayswapbayswap.exeHot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices
    UBayswap2TbUpdate.exeHot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices
    NBBC AlertsBBC_Alerts.exeBBC Alerts - "You can now have all the latest news and sports headlines delivered straight to your desktop with the new BBC Alerts service"
    UBBC News alertsskinkers.exeBBC News Desktop Alerts service - see here. Desktop alert and breaking news e-mail services let you find out about all the latest news as it happens
    ?BBDialBT Broadband.exePart of BT Broandband - is it required?
    NBBLauncher.exeBBLauncher.exeBounceBack Professional - back-up software
    NbbSysTraybbSysTray.exePhilips CD-RW related - "the 'Blue Button' feature gives users the chance to receive convenient online support for their possible device problems or questions"
    Ubbuibbui.exeAOL DSL status monitor displaying a red/green icon indicating if you have a connection
    Ubcabca.exeBeClean Agent - registry, history, temp files, etc cleaner
    UBCDetectbcdetect.exeBcdetect.exe searches the system to make sure Creative drivers are installed for the video card. It loads the BlasterControl when the drivers are detected. Your choice - try it and see
    YBCMDMMSGbcmdmmsg.exeBCM voicemodem driver. Required for dial-up if you have one of these modems
    UBCMHalrundll32.exe bcmhal9x.dll, bcinitBlasterControl for Creative video cards - controls for desktop settings, monitor configuration, colour adjustments and performance tuning. May be needed to retain settings
    YBCMSMMSGBCMSMMSG.exeBCM voicemodem driver. Required for dial-up if you have one of these modems
    ?bcmwltrybcmwltry.exeBroadcom Corporation Wireless Network Tray Applet. Is it required?
    NBCNTbcnt.exeAWS Weatherbug related. What does it do?
    XBCPCbcpc.exeBroadcastPC adware variant
    Xbcpc_cbcpc_c.exeBroadcastPC adware variant
    UBCTweakbctweak.exeBlasterControl for Creative video cards - controls for desktop settings, monitor configuration, colour adjustments and performance tuning. May be needed to retain settings
    XBcvsrv32bcvsrv32.exeAdded by the GAOBOT.BQJ WORM!
    XBcvsrv32he3.exeAdded by the AGOBOT.AKB WORM!
    XBcvsrv32msxml22.exeAdded by the AGOBOT.AKH WORM!
    NBCWipeTMbcwipetm.exeBCWipe Task Manager - scheduler for BCWipe so that it runs at convenient times. You can set a time for running the task, as well as special options for the task. Run manually when needed
    XBDdc.exeAdded by the RASDOOR-A TROJAN!
    UBDAgentbdagent.exeBitDefender antivirus
    YBDMConBdmcon.exeBitDefender antivirus
    YBDNewsAgentbdnagent.exeBitDefender antivirus - updater
    YBDOESRVbdoesrv.exeBitdefender 8 antivirus and firewall
    YBDSwitchAgentbdswitch.exeBitdefender 8 antivirus and firewall
    UBearFlixBearFlix.exeBearFlix is optimized for the fast download of video files
    NBearSharebearshare.exeBearShare file sharing client. Versions known to include spyware - see here
    UBeatNik Internet ClockBeatNik.exeBeatNik Internet Clock is a Windows clock add-on that supports 'skins'. It can also synchronize your computer's clock with an atomic clock
    XBeawversaqevre.exeAdded by a variant of the RANKY TROJAN!
    XBeegees Updatebeegees.exeAdded by the SDBOT-ADK WORM!
    ?BEEIbeei.exe??
    UBeFasterbefaster3.exeBeFaster internet connection optimization tool
    ?BEHLBEHL.exe??
    ?BEHLOBEHLO.exe??
    Ubeidsystemtraybeidsystemtray.exeRelated to Belgium Identity Card card reader
    NBelkin PCMCIA WLAN Monitormonitorbk.exeBelkin USB Network Adapter Management utility - can be started manually
    NBelkin Wireless UtilityBelkinwcui.exeWireles configuration utility for some Belkin cards such as the Wireless G Desktop Card
    UBellSouthAlertManager.exeBellSouthAlertManager.exeRelated to BellSouth Alert Manager
    UBelNotifyrundll32.exe [path] NPBelv32.dll, RunDll32_BelNotify"BelTech from Belarc enables licensees to offer automated, Web-based problem resolution to their end-users. BelTech allows the end-user to simply go to a web page and automatically resolve their problem or point them to the right solution. BelTech Manager allows non-programmers to rapidly and easily deploy and maintain this service"
    ?BELORVBIBELORVBI.exe??
    ?Belsta.exeBelsta.exeConfiguration tool for Belkin wireless network cards. Required to change the card's configuration. Is it required for correct operation once the confuiguration is changed?
    XBeltBelt.exeVX2.Transponder parasite updater/installer related
    XBenadril Alert Toolbenadrilalert.exePlug-in for WeatherBug advising when pollen count in your area is high - prompting you to buy Benadril
    UBestCrypt Auto OpenBestCrypt.exeBestCrypt from Jetico, Inc. "Keeps your confidential data in a strongly encrypted form on your disk and provides you with transparent access"
    XBestPopUpKillerBestPopupKiller.exePopup killer by Swanksoft - not recommended, see here
    XBeSys[path to file]BeSys adware
    Xbetasvchost.exeAdded by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
    XBF4Pbf4p.exeAdded by the IRCBOT.GEN WORM!
    Ybgbullguard.exeBullguard antivirus and firewall. The P2P version is free with KaZaA Media Desktop and Grokster
    UBGInfoBginfo.exeBGinfo automatically displays relevant information about a Windows computer on the desktop's background, such as the computer name, IP address, service pack version, and more
    UBgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}NMBgMonitor.exeAssociated with Nero Scout, added by version 7 of the Nero digital media suite (CD & DVD burning, authoring, etc). Thanks to Help2Go.com, if you feel this is draining more resources that necessary you can disable it by clicking here
    YBGNewsAgentbgnewsag.exeBullGuard antivirus updater
    Nbgsmsndbgsmsnd.exePrinter driver to generate PDF files from any program
    XBharatayudaGNB.exeAdded by the BHARAT.A WORM!
    NBHOCopBHOCop.exePC Magazine's BHO Cop that lets you see what browser helper objects are installed. Useful for detecting spyware
    UBHODemon 2.0BHODemon.exeBHODemon "protects you from unknown Browser Helper Objects (BHOs), by letting you enable/disable them individually. When running, it also monitors your Registry and alerts you when a BHO is installed. Best of all, BHODemon knows about the most common BHOs - the good ones, and the not-so-good ones!". If you prefer forgoing resident protection, the application can also be run on demand
    UBHRBHR.exeBrowser Hijack Retaliator - recovers your browser after it has been hijacked by spyware, adware, etc
    UBI1HelperStartUpBI1HEL~1.EXEScreenScenes "Beach Islands" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here
    XBIERundll32.exe [path] BDSrHook.dll, Rundll32BDplugin parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
    XBIGbiggy.exeAdded by the DELBOT-AG WORM!
    UBigDog303VM303_STI.EXERelated to VIMICRO USB for PC Camera
    NBigDog305VM305_STI.EXEVmicro webcam USB utility - allows the webcam to initiate data transfer to a program. Create a shortcut and start it manually when needed
    ?BigDogPathVM_STI.EXEBundled with some software for digital cameras that use a USB connection - what does it do and is it required?
    NbigfixBIGFIX.EXEBigFix can automatically download and read technical support information provided by computer and software manufacturers and other technical support experts (published in the form of Fixlet? Messages) and can automatically check your computer for bugs, configuration conflicts, and security holes. Should only be started manually as it's a resource hog
    Xbigorisbigoris.exeAdded by the DORF-AZ TROJAN!
    UBigPond ToolbarbpumTray.exeTelstra BigPond Toolbar - "Introducing the free and easy to use BigPond Toolbar that is designed to make your internet experience and managing your Telstra internet account a whole lot easier"
    NBigPondCablebpcable.exeTelstra Bigpond Cable login software - can be started manually
    YBigPondWirelessBroadbandCMBigPond_CM.exeRelated to BigPond_Wireless_Broadband Service by Telstra
    Xbikinibikini.exeAdded by the LOWZONE-CX TROJAN!
    XBillGatesLoh.exeBillGatesLoh.exeAdded by the AGENT-FZO TROJAN!
    NBillminderBillmind.exeCan be setup in Quicken to remind user of due payments. Available via Start -> Programs
    Xbin32hpuppstub.exePrecisionPop adware
    XbingdianBingdian.vbsAdded by the BINGD WORM!
    ?Bingo Charmcharms.exeSome kind of screen icon kind of like desk flag, but it gives you a choice of icons?
    UBiomenumenusw.exeRelated to Sony VAIO - passwords, encryption, and a biometric fingerprint sensor
    XBiosBios32.exeAdded by an unidentified VIRUS, WORM or TROJAN!
    Xbiosbios.exeAdded by the BANCBAN-PW TROJAN!
    XBIOS XP Loader[random filename]Added by the RBOT-IC WORM!
    XBIOS1BIOS1.EXEAdded by the OPASERV.T WORM!
    ?BIOVCIPBIOVCIP.exe??
    NBitCometBitComet.exeBitComet P2P client - can be launched from Start -> Programs
    YBitDefender Antiphishing HelperIEShow.exeAntiphishing component of BitDefender 2008 products
    XBitDefender AntivirusBITDEFENDERX.EXEAdded by a variant of the SPYBOT WORM!
    YBitDefender Communicatorxcommsvr.exeBitDefender antivirus
    UBitDefender for MSN Messengermsnmon.exeBitdefender anti-virus for MSN Messenger - no longer supported at the BitDefender website
    UBitDefender for Yahoo! Messengeryahmon.exeBitdefender anti-virus for Yahoo! Messenger - no longer supported at the BitDefender website
    YBitDefender Live! Initbdinit.exeBitDefender antivirus
    YBitDefender Scan Serverbdss.exeBitDefender antivirus
    YBitDefender Virus Shieldvsserv.exeBitDefender antivirus
    Ybitdefenderliveavxlive.exeMain program of BitDefender virus scanner/firewall
    UBitDefender_P2P_StartupBitDefender_P2P_Startup.exeBitdefender anti-virus for P2P clients - no longer supported at the BitDefender website
    UBitTorrent DNAbtdna.exe"BitTorrent DNA is a content delivery service that uses a secure, private, managed peer network to power faster, more reliable, more efficient delivery of richer content"
    NBitWare Print Monitorbwprnmon.exeFaxServe network fax software
    NBJ Printer Status MonitorCjstsr.exeCanon BJ printer status monitor
    NBJ Status Monitor 5xxCJSTRxx.EXECanon printer status monitor - where "xx" is different depending upon the version. Not required as you can check the printer status via My Computer -> Printers
    Nbjcfdcdf.exeBroadJump Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programs
    UBJPD HID ControlTVMon.exeRelated to Canon Photo viewer
    NBlackICE PC Protectionblackice.exeLoads the user interface for the BlackICE PC Protection (was Defender) firewall program. From the parent site - '(the user interface) starts in the "Startup" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' See also LoadBlackD
    NBlackIce Utilityblackice.exeLoads the user interface for the BlackICE PC Protection (was Defender) firewall program. From the parent site - '(the user interface) starts in the "Startup" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' See also LoadBlackD
    Ubladsblads.exeA Tweak-XP component, blocks advertisement banners in Internet Explorer. Can be enabled/disabled via Tweak-XP / Internet Tweaks
    Xblah servicewinupdate.exeAdded by the GAOBOT.BIA WORM!
    Xblah servicewinsysengine.exeAdded by the RBOT-KI WORM!
    Xblah serviceinternet.exeAdded by a variant of the RBOT WORM!
    Xblah servicesmnp.exeAdded by the RBOT.IZ WORM!
    Xblah servicemsnmsgrr.exeAdded by the RBOT.PZ WORM!
    Xblah servicetazkmgr.exeAdded by the RBOT.UA WORM!
    Xblah serviceFaLeH.exeAdded by the RBOT-AES WORM!
    Xblah servicemicrosoft.exeAdded by a variant of the RBOT WORM!
    Xblah serviceevosys.exeAdded by a variant of the RBOT WORM!
    Xblah servicewin32.exeAdded by the RBOT-AXO WORM!
    XBlah serviceCCAPPS32.EXEAdded by the RBOT.TV WORM!
    Xblah servicesiczw.exeAdded by the RBOT-GMP WORM!
    Xblahh servicemsengine.exeAdded by a variant of the RBOT WORM!
    Xblahx servicemsnjompa.exeAdded by the SDBOT.AML WORM!
    XBlank AntiViriAUT0EXEC.BATDetected by Symantec as the SILLYFDC WORM! See here
    NBlazeChangerFBZPaper.exeEmber graphic file viewer, manager, and touch-up system
    Nbldbubgbldbubg.exePart of Dell Alerts which provides customers with an update on latest updates for his/her system
    XBLFblf.exeAdded by the DELBOT-M WORM!
    Ublinkxblinkx.exeBlinkx Desktop "Smart Folders" software
    NBlitzz BWI715WLANmon.exeBlitzz Technology BWI715 Wireless PC modem connection monitor
    XBLMessagingIntegrationblengine.exeBuddyLinks adware
    UBlockAdsblads.exeA Tweak-XP component, blocks advertisement banners in Internet Explorer. Can be enabled/disabled via Tweak-XP / Internet Tweaks
    XBlockCheckerBlock-checker.exeBlockChecker adware
    XBlocker System611 MonitoringPopUpBlocker611.exeAdded by the RBOT.BLJ WORM!
    NBlockTrackerBlockTracker.exeIf present on a HP machine it tracks all the processes and logs them to a blocklog.txt file
    UBLOGrundll32.exe [path] BatLogEx.DLL, StartBattLogIBM Thinkpad battery management utility that logs changes in battery conditions such as charging, discharging, etc
    Ublsloaderblsloader.exeBellSouth ISP Internet Tools
    Xblssblss.exeAdded by the BLARUL TROJAN!
    NBLSTAPPblstapp.exePuts access to Creative's BlasterControl in the System Tray
    NBlubsterBlubster.exeRelated to Blubster Music sharing service
    UBlue Frogbluefrog.exeBlue Frog by Blue Security Inc. - actively fights spam by posting complaints on the sites advertised by the spam you receive
    XBlue Service[path to trojan]Added by the BANCOS-BCW TROJAN!
    ?BlueLight_uoltrayexec.exeRelated to BlueLight Internet. What does it do and is it required?
    UBlueSoleilBLUESO~1.EXEBlueSoleil Bluetooth wireless manager from IVT Corporation
    UBlueSpace NEBlueSpaceNE.exe"BlueSpace NE is a utility program used to run the Bluetooth function on VAIO computers that support the Bluetooth function or on VAIO computers connected to the Bluetooth USB adapter". Shortcut available via Start -> Programs
    XBluetooth Configbtwindin32.exeAdded by the SDBOT-DFN WORM!
    UBlueToothAuthentication AgentRunDLL32.exe irprops.cpl, BluetoothAuthenticationAgentAssociated with BlueTooth software, designed to allow bluetooth mobile devices to authenticate to the computer, when connecting a PDA to your computer - necessary for the computer and the PDA to communicate. Should you get the error message, "Rundll irprops.cpl missing entry Bluetooth authentication agent", click here for more information. In case you no longer have BlueTooth support installed, and don't need it, simply uncheck the entry in Msconfig > Startup
    UBlueyonder Instant Support Toolmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". Blueyonder Instant Support is required to run with the Help and Support program. If you uncheck it and and then run Help and Support it will add another Blueyonder Instant Support in the startup menu. If you remove Blueyonder Instant Support in add/remove programs some help menus in help and support will not be available. You decide
    NBMail InstallationFTP_back.exePart of iMesh - a file sharing system. Reported by Norton AntiVirus as a trojan. Once deleted does not prevent file sharing working. Older versions of iMesh re-instate this but the newer versions do not
    XBmanBMan1.exeAbcsearch.com/DealHelper adware variant
    UBMMGAGRundll32 PWRMONIT.DLL, StartPwrMonitorDisplays a battery gauge icon in the Taskbar (not the System Tray). Provides shortcuts to IBM's proprietary power saving settings and to a battery information window
    UBMMLREFBMMLREF.EXEBattery Manager for IBM ThinkPad laptops
    UBMMMONWNDrundll32.exe [path] BatInfEx.dll, BMMAutonomicMonitorBattery power management utility for Lenovo (IBM) ThinkPad laptops
    UBMO MasterCard WalletEWALLET.EXEThe wallet conveniently stores billing, shipping and payment information on your PC
    NBMupdateBMupdate.exeRelated to the BookmarkCentral entry. Typically added after downloading drivers for Visioneer scanners for example, and you install the driver self-install
    XBMZbmz.exeNCase adware
    XBndt32Bndt32.exeAdded by the LACON WORM!
    XBnexe[random filename]Added by the KITRO.D (or ARGEN.A) WORM!
    UBO1HelperStartUpBO1HEL~1.EXEScreenScenes "Butterfly Oasis" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here
    UBO1HelperStartUpBo1helper.exeScreenScenes "Butterfly Oasis" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here
    XBoarddata[path] repcale.exe [path] palsp.exeAdded by a variant of the RANDON.AN WORM!
    Xboat32boat32.exeAdded by a variant of the RBOT WORM!
    Xbobycsrs.scrAdded by the BANCBAN-PC TROJAN!
    YBOC-423BOC423.exeNSClean BOClean (now Comodo) anti-malware software - "Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely". Version 4.23
    YBOC-424BOC424.exeNSClean BOClean (now Comodo) anti-malware software - "Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely". Version 4.24
    YBOC-425BOC425.exeComodo BOClean anti-malware software - "Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely". Version 4.25
    YBOC412BOC412.exeVersion 4.12 of NSClean's BOClean anti-trojan software
    YBOCleanautostartBoclean.exeNSClean's BOClean anti-trojan software
    UBOINC Managerboincmgr.exeBOINC manager - "controls the use of your computer's disk, network, and processor resources"
    UBoingo Wireless UtilityIcon###XXX#X#.exeStarts the Boingo Wireless utility, used to detect and login into Boingo wireless hotspots. The filename may be autogenerated when installing, two different variations along the lines listed here, where # is a number and X is a letter. Shortcut available via Start -> Programs
    Xbolenjabolenja.exeAdded by the WANTVI.BF TROJAN!
    Xbolenjxbolenjx.exeAdded by the ELDYCOW.O TROJAN!
    Xboler.exesyser.exeAdded by the RBOT-AYS WORM!
    UbombshelBOMB32.EXEPart of McAfee Nuts & Bolts. Protects your Windows system from application failure and crashes - similar to Norton Crashguard. Your choice - may cause problems
    XBonzi Buddy??Bonzi Buddy adware - see here for removal instructions
    Xbooboo.exeAdware downloader - detected by Kaspersky as the FAVADD.O TROJAN!
    XBookedSpaceRunDLL32.EXE bs2.dll, DllRunBookedSpace parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "bs2.dll" file is located in the Winnt or Windows folder
    NBookmarkCentralBMLauncher.exeBookmark Express - "offers a more flexible way to manage Web site bookmarks, regardless of which browser you use"
    NBookMarkSinksyncit.exeBookmark synchronization utility
    NBookMarkSyncsyncit.exeSync2IT BookMarkSync - "real-time automatic synchronization service that allows you to access your bookmarks, favorites and favorite files from any computer or any browser". Only installed with the users explicit permission and generally only remains running if the user decides to subscribe to the service. If it is no longer required it should be uninstalled to prevent a large number of clients 'checking in' to the server that have no chance of synchronizing
    NBookMarkSync2Itsync2it.exeSync2IT BookMarkSync - "real-time automatic synchronization service that allows you to access your bookmarks, favorites and favorite files from any computer or any browser". Only installed with the users explicit permission and generally only remains running if the user decides to subscribe to the service. If it is no longer required it should be uninstalled to prevent a large number of clients 'checking in' to the server that have no chance of synchronizing
    UBoost XP Servicebxservice.exeBoost XP from Systweak - WinXP tweaking utility
    Xbootboot.exeAdded by the PUPPET-A TROJAN! Located in the System (9x/Me) or System32 (NT/2K/XP) folder
    UBootBoot.exePart of Acer Empowering Technology. "Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles, or to create their own customized profiles". Located in the "AcerEmpowering TechnologyePower" directory
    XBoot Checkbootchk.exeAdded by the DELBOT-AB WORM!
    XBoot Configbootconfig.exeAdded by the FLOOD-EV TROJAN!
    XBoot ManagerNjgal.exeAdded by the KILO TROJAN!
    XBoot Managerbootmng.exeAdded by a variant of the SPYBOT WORM!
    XBootCfgInstall.log.vbsAdded by the YPSAN.D WORM!
    XBootCTRLbootctrl.exeAdded by an unidentified WORM or TROJAN!
    XBootLoaderBootLoader.exe.vbsAdded by the WATERWORKS WORM!
    Xbootpd.exebootpd.exeAdded by the AGENT-DT TROJAN!
    XBootsCfgwscript.exe [path] Date.POP.vbsAdded by the KUULLIO WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted
    XBootsCfgwscript.exe [path] All Users.vbsAdded by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted
    XBootsCfgwscript.exe [path] All Users.vbeAdded by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted
    XBootsCfgwscript.exe Install.log.vbsAdded by the YPSAN.E WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "Install.log.vbs" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    UBootStatusBOOTST~1.EXEVisual Basic program that pops up a small window on startup telling you how many times the machine has been booted that day.  Once you exit it, it has no more effect on resources
    UBootWarnBootWarn.exeFrom here: "Norton AntiVirus Boot Warning. This program is installed as a startup item when you install Norton AntiVirus, and also sometimes when you do a LiveUpdate which updates Norton AntiVirus significantly enough that a reboot is needed to complete the installation. We believe its purpose to be to warn the end-user that he must reboot his PC before using Norton AntiVirus in those cases when a reboot did not happen with the result that Norton AntiVirus did not fully complete its installation or software updating. Recommendation : Start Norton AntiVirus from "Start Programs Norton AntiVirus". If Norton AntiVirus comes up without problems, then fix this entry from the Msconfig Startup tab - it was left behind by mistake and is no longer needed now that Norton AntiVirus is fully installed and opens without error messages"
    Xboot_reg[path to file]Added by the BANCBAN-CA TROJAN!
    NBose Wave/PC Monitorwavepcmonitor.exeSystem Tray access for this system (more info on the system here). Available via Start -> Programs
    XBossIdeawinlogin.exeAdded by the LINEAGE-I TROJAN!
    ?BostonBoston.exePart of the Boston Acoustics USB speaker systems. What does it do and is it required?
    XBot Loadersvchostt.exeAdded by the GAOBOT.ALV WORM!
    XBouncer RunStartupbouncer.exeVirtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see here
    XBouncer RunStartupLiveUpdate.exeVirtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see here
    Xboy lovers of bsdilikeboys.exeAdded by the MYTOB.LY WORM!
    Ubpcpost.exebpcpost.exeMS TV Viewer Post Setup Program. Part of MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
    XBPCv2 rebpc2 re inst.exeBroadcastPC adware variant
    UBPKbpk.exeBlazing Tools Perfect Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!
    NBPServerG6FTPSrv.exeBulletProof FTP Server
    UBQTray.exeBQTray.exeSystem Tray access to BurnQuick CD burning software. Only required if you use the queueing facility, hence the U recommendation. Create your own desktop shortcut to start manually
    XBrasilBrasil.exeAdded by the OPASERV.E WORM!
    XBrasilBRASIL.PIFAdded by the OPASERV.E WORM!
    XBrasilOld[worm filename]Added by the OPASERV.P WORM!
    XBraveSentryBraveSentry.exeBraveSentry spyware remover - not recommended, see here
    Xbraviaxbraviax.exeAdded by an unidentified malware
    XBrcttrdb.exeDetected by Kaspersky as the PURITYSCAN.Y TROJAN!
    UBreak_ReminderBREAK REMINDER.exeBreak Reminder - Remind yourself to take breaks to prevent computer related injuries. See here
    YBredbandsbolagetservicecenter.exeRelated to the Brebband Swedish Broadband provider
    XBregbcre.exeBroadcastPC adware variant
    XBregbptre.exeBroadcastPC adware variant
    XBregbreg.exeBroadcastPC adware variant
    XBridgerundll32.exe ...Bridge.dllFlingstone.com browser hijacker
    YBrindys BriTrayBRITRAY.EXEMain process for the following applications: GEDEX, SICARIO, BRINOTES, BRIRESPA, SICURE, TRASGO, UNDOCS, FRESH & BRIFAME (all of them from Brindys Software). Performs the following tasks [un]installation, web software autoupdate, notification windows, interprocess communication, tray bar icons & menus, alarms (brinotes), and common web launching from the mentioned applications. Can be stopped safely once run if so desired
    UBrmfRmPABrmfRmPA.exeBrother resource manager - needed for a Brother MFC printer/copiert/scanner and PC to properly communicate
    Ubroadband medicmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". ntlbroadband Help is required to run with the Help and Support program. If you uncheck ntlbroadband Help and and then run Help and Support it will add another ntlbroadband Help in the startup menu. If you remove the ntlbroadband Help in the add/remove program some help menus in help and support will not be available. You decide
    NBroadband Wizardbbwiz.exeStarts Broadband Wizard so it runs in the System Tray. This application tests and optimizes your Cable or DSL connection. Available via Start -> Programs
    NBroadCamRunbroadCam.exeBroadCam is an easy to use video streamer designed to broadcast live video using a webcam (or other camera) and microphone
    UBroadcom Wireless Manager UIbcmntray.exeRelated to Broadcom Network Adapters for additional configuration options for these devices. Should not be terminated unless suspected to be causing problems
    NBroadcom Wireless Manager UIwltray.exeSystem tray access to wireless LAN card configuration options
    XBron-SpizaetusCVT.exeAdded by the RONTOKBRO WORM!
    XBron-SpizaetusnorBtok.exeAdded by the RONTOKBRO.B WORM!
    XBron-Spizaetus[path to file]Added by the BRONTOK-F WORM!
    XBron-Spizaetusbronstab.exeAdded by the RONTOKBRO.C WORM!
    XBron-Spizaetuseksplorasi.exeAdded by the RONTOKBRO.J WORM!
    XBron-SpizaetusElnorB.exeAdded by the RONTOKBRO.D WORM!
    XBron-Spizaetussempalong.exeAdded by the BRONTOK-E WORM!
    XBron-SpizaetusRakyatKelaparan.exeAdded by the BRONTOK-J or BRONTOK-L WORMS!
    XBron-Spizaetus-5118REPMkomodo-6321422.exeAdded by the BRONTOK-R WORM!
    XBron-Spizaetus-cfgmktoqbbm-qotkmgfc.exeAdded by the BRONTOK-M WORM!
    XBron-Spizaetus-cfgmmnrubbm-urnmmgfc.exeAdded by the BRONTOK-N WORM!
    XBrowseProxyFindService.exeActual Names (AdvSearch) Internet Keywords parasite
    Xbrowsermsgaol.exeAdded by the TACTSLAY.C TROJAN!
    Xbrowsers_menu.exeAdded by the TACTSLAY.C TROJAN!
    Xbrowserbrowse.exeAdded by the TACTSLAY.C TROJAN!
    Xbrowserdeamon.exeAdded by the TACTSLAY.C TROJAN!
    Xbrowsermsgaol.exeAdded by the TACTSLAY.C TROJAN!
    Xbrowser aidbrowseraid.exeBrowserAid/BrowserPal foistware
    XBrowser Help SvcBHSV.EXEAdded by the RBOT-AVQ WORM!
    YBrowser Hijack Blasterbhblaster.exeBrowser Hijack Blaster - protects your system from browser hijackers and spyware that alters your IE settings. Now replaced by SpywareGuard
    UBrowser LauncherCommandr.exeLogitech internet keyboard "Commander" software - loads the software for the shortcut keys on the keyboard. Not required unless you want to use the short cut keys
    XBrowser Paladblck.exeBrowserAid/BrowserPal foistware
    UBrowser SentinelBrowserSentinel.exeBrowser Sentinel - notifies you if a program wants to penetrate into Internet explorer, add itself to the Windows auto-run list or change your home page
    XBrowserUpdateSched[random filename]ZenoSearch adware
    NBrowserWebCheckloadwc.exeChecks to make sure that IE is still your default browser
    XBrO_AcTBrO-AcT.exeAdded by the SILLYFDC-D WORM!
    Xbrwdiag[path to worm]Added by the STRATIO-BN WORM!
    NBS Playerbsplayer.exeBSplayer - A video player used to play avi, mpg, wmv and other multimedia files
    NBsCLiPBSCLIP.exeCD recording utility that comes with a lot of CDR/CDRW drives and isn't required
    XBsoft lppt01Bsoft.exeRapidBlaster variant (in a "BelmontSoft" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
    Nbsplayerbsplayer.exeBSplayer - a video player used to play avi, mpg, wmv and other multimedia files
    XBSserverFileKan.exeAdded by the VB.CBW WORM!
    XBSVCHOSTSVCH0ST.EXEAdded by the VOXOM TROJAN!
    XBsx3RunDLL32.EXE bs3.dll, DllRunBookedSpace parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "bs3.dll" file is located in the Winnt or Windows folder
    XBT[path to trojan]Added by the LITEBOT-B TROJAN!
    UBT Broadband Desktop Helpmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". BT Broadband Help is required to run with the Help and Support program. If you uncheck BT Broadband Help and and then run Help and Support it will add another BT Broadband Help in the startup menu. If you remove the BT Broadband Help in the add/remove program some help menus in help and support will not be available. You decide
    UBT Broadband Helpmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". BT Broadband Help is required to run with the Help and Support program. If you uncheck BT Broadband Help and and then run Help and Support it will add another BT Broadband Help in the startup menu. If you remove the BT Broadband Help in the add/remove program some help menus in help and support will not be available. You decide
    XBT00003*abcdefg23.exeAdded by the VB-VT TROJAN where * = 5,6 or 7!
    XBT00003*hiklmnop27.exeAdded by the VB-VT TROJAN where * = 2,3 or 4!
    Ubtbb_wcm_McciTrayAppMcciTrayApp.exeSystem tray access to Motive's Broadband 2.0 configuration and repair utility
    ?btinstbtinst.exeAssociated with an Anycom bluetooth wireless card. What does it do and is it required?
    UBTModemProtectionBTModemProtection.exeBT Privacy Online modem protection software, see here
    UBTopenworldDialBTYahoo.exeBT Yahoo! internet connection manager
    ?BTSETBOOTKEYBTSetBootKey.exeRelated to a USB Bluetooth adaptor. What does it do and is it required?
    UBtStartbtstart.exeBroadcom (formerly WIDCOMM) Bluetooth Connectivity Software
    Ubttraybttray.exeSystem tray icon which shows the status of a BlueTooth wireless module. Most systems with such a module installed can enable/disable the module. The system tray icon changes from blue/white to blue/red when the module is turned off. Allows access to explore bluetooth places, setup wizard, advanced configuration, quick connect and shutdown device
    YBTUSRBDGBtUsrBdg.exeUsed with a Mitsumi USB Bluetooth adaptor (and maybe others)
    YBTUSRBDGFBtUsrBdg.exeUsed with a Mitsumi USB Bluetooth adaptor (and maybe others)
    XBTVbtv.exeBroadcastPC adware variant
    YBubbleBubble.exeAdded by Windows SteadyState which "helps make it easy for you to keep your computers running the way you want them to, no matter who uses them." Bubble allows notification messages to appear on a computer managed by Windows SteadyState
    NBuddyizerBuddyizer.exePart of the AIMster Peer to Peer (P2P) file sharing application that runs over the AOL Instant Messenger network
    UBUFFALO Power Save Utility for HDHDManage.exePower Save utility for Buffalo backup hard discs
    NBug EliminatorBug_Elim.exeBug Eliminator - "performs a complete health check on your computer safely, securely, and silently!"
    Ubugwatcher servicebugwatcher.exeBugtoaster is a service that sends reports on system/program crashes (certain types) back to Bugtoaster. They relay information to program authors and provide, if available, any known solutions to the crashes. It doesn't take up any room in memory, just activates in the event of certain program failures
    NBuildBUbldbubg.exePart of Dell Alerts which provides customers with an update on latest updates for his/her system
    XBuildLabservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
    XBuildLabwinlogon.exeAdded by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
    XBuildLabscsrss.exeAdded by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
    XBuildLabslsass.exeAdded by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder
    UBulldog Serviceupsd.exeBelkin's Bulldog Plus control software which runs under Windows 95 or later and monitors the UPS (Uninterrupted Power Supply) via a serial or USB link
    NBulletProof FTP Serverbpftpserver.exeBulletProof FTP Server
    YBullGuardmgui.exePart of Bullguard antivirus
    YBullGuardBullGuard.exePart of BullGuard antivirus
    UBullGuard Updateavxlive.exePart of Bullguard antivirus. Leave enabled unless you manually update virus definitions
    YBullGuard XCommXCOMMSVR.EXEPart of Bullguard antivirus
    YBullGuardInitAVXINIT.EXEPart of Bullguard antivirus
    YBullguardoptInbulldownload.exePart of Bullguard antivirus
    XBullsEyebargains.exeBargainBuddy adware
    XBullsEye Networkbargains.exeBargainBuddy adware
    ?BullsEye TrackerBeTrack.exeBullseye - intelligent research assistant
    XBunxbeagle.exeAdded by the LEBREAT-E WORM!
    NBurnQuick QueueBQTray.exeSystem Tray access to BurnQuick CD burning software. Only required if you use the queueing facility, hence the U recommendation. Create your own desktop shortcut to start manually
    UButton Serverbttnserv.exeFound on a Compaq PC, for the extra buttons on the keyboard for the speaker volume, media player, sleep and internet buttons. If the buttons aren't used on the keyboard or your's doesn't have them, then it isn't required
    NButtonKeyButtonKey.exeCyberView TWAIN driver for the Pacific Image range of 35mm film scanners. Enables the one touch scanning button and places an icon an the System Tray. Use your scanners software or run it manually by creating a shortcut
    NBuzmeBmui.exeBuzme by RingCentral, Inc - internet call waiting. Intercepts telephone calls like an answering machine and plays the voice message on your PC. Only required when you're on-line and via dial-up modem
    UBuzMeRCUI.exeDisplay Client for the BuzMe Internet Call Waiting Service
    UBuzof.exebuzof.exeBuzof from Basta Computing "enables you to automatically answer, close or minimize virtually any recurring window including messages, prompts, and dialog boxes"
    Nbwprnmon.exebwprnmon.exeFaxServe network fax software
    Xbxproxybxproxy.exeAdded by the BXPROXY TROJAN!
    Xbxproxy[random].dllSpyware Soft Stop misleading security software - not recommended, see here and here
    Xbxsx5RunDLL32.EXE bsx5.dll, DllRunBookedSpace parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "bsx5.dll" file is located in the Winnt or Windows folder
    Xbxxs5RunDLL32.EXE bxxs5.dll, dllrunBookedSpace parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "bxxs5.dll" file is located in the Winnt or Windows folder
    XBymer.ScannerWininit.exeAdded by the BYMER WORM!
    XBymer.ScannerMsinit.exeAdded by the BYMER WORM!
    UBySoft FreeRAMFreeRAM.exe"Bysoft FreeRAM is a program that frees up ram manually or automatically. It shows current memory status , memory load and CPU usage graphically". MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
    Xcc:archiv~1win.comAdded by the CUYDOC TROJAN!
    UC-Media Echo ControlEchoCtrl.exeC-Media produce audio chipsets that are often found on popular motherboards with on-board audio. You may need it if you use the echo control feature of C-Media Mixer
    NC-Media MixerMixer.exeC-Media produce audio chipsets that are often found on popular motherboards with on-board audio. Provides System Tray access to change audio settings. Available via Start -> Settings -> Control Panel or Start -> Programs
    UC2KCYB2K.EXECYBERsitter 2000 or 2001 - anti-adult content filter primarily. Required if you want the sites you visit filtered without having to load the software every time you launch your browser
    Uc32cs2c32cs2.exeCyber Sentinel - internet filtering software
    XC7[path to worm]Added by the MEDIAKILL.A WORM!
    UC:\Program Files\NetMeter\NetMeter.exeNetMeter.exe"Net Meter is a small, customizable network bandwidth monitoring program for Win9x/Me/NT4/2K/XP. NetMeter is and will always stay freeware. The program has been tested extensively on Win2K/XP, but it should work just as well on all other Win32 operating systems"
    XC:\WINDOWS\IEXPLOR.EXEIEXPLOR.EXE"Pop Marketing" adware
    XC:\WINDOWS\system32\SetupCmd.exeSetupCmd.exeDetected by Kaspersky as the AGENT.AAW TROJAN!
    XC:\WINDOWS\WinTask.exeWinTask.exe"Pop Marketing" adware
    UCA-AMAgentamagent.exeUnicenter Asset Management is a solution for proactively managing IT assets in a business environment. It provides full-featured asset tracking capabilities through automated discovery, hardware inventory, network inventory, software inventory, configuration management, software usage monitoring, license management and extensive cross-platform reporting
    YCaAvTrayCAVTray.exeeTrust? EZ Antivirus system tray application from Computer Associates
    XCabchkCabchk.exeAdded by the GEMA TROJAN!
    XCabchk32Cabchk32.exeAdded by the GEMA TROJAN!
    XCABCInstallCABCInstall.exeIgnite Technologies (was CABC) content delivery software
    XCable Modem AdapterWindowsSec.exeAdded by the WOOTBOT.A WORM!
    UCacheBoosttrayicon.exeCacheBoost "optimizes the System Cache-Management of Windows XP/2000/NT and Windows .Net Servers, resulting in a performance boost"
    XCacheLoader[path to trojan]Added by the DLOADER-NZ TROJAN!
    NCachemanCacheman.exeFreeware disk cache tweaker from Outer Technologies. Should only be run once and not loaded at start-up
    YCacheMgrCacheMgr.exeSophos Antivirus Remote Update
    UCacheSentry ProCacheSentry Pro.exe"CacheSentry Pro is a program that takes over the management of the Internet Explorer (and AOL) web browser cache"
    UCacheSentry ProCacheSentry Pro.exe"CacheSentry Pro is a program that takes over the management of the Internet Explorer (and AOL) web browser cache"
    NCACStartercacstart.exeCash A Check - check writing software
    UCaddais BackupOnDemandBODMon.exeCaddais BackupOnDemand - "runs in the background and monitors your important files for changes. Within seconds of changing, modified files are automatically backed up to an archive location"
    UCadenzaCdzSvc.exeCadenza mNotes for Palm and Pocket PC enables users to access Lotus Notes on their mobile devices
    UCADScads.exeCyber Sentinel - internet filtering software
    UCafeStationCafeStation.exe"CafeSuite is the solution for your internet cafe. Our software provides you with ameans to control the workstations, manage customer database, sell products and generate detailed reports and statistics"
    Ycafwccafw.exeCA Personal Firewall - part of the CA Internet Security Suite
    NCAgentCAgent.exeAbbyy Fine Reader OCR (Optical Character Recognition) software for scanning and converting documents
    XcAgOu[filename].htaAdded by the KAKWORM WORM!
    NCahootWebcardCahootWebcard.exe"The Cahoot Webcard is a virtual card that allows you to use your Cahoot credit card online without ever having to expose your real card numbers over the web. It works by generating one-off transaction numbers as a substitute for your real cahoot credit card details". Run manually when needed
    Xcaidiysetupdiynetsetupuni.exeDIYNet adware
    YCAISafeisafe.exePart of Computer Associates eTrust EZ Antivirus
    UCaISSDTcaissdt.exeComputer Associates Dashboard Tray applet
    NCal Reminder Shortcutcalrem.exeProduces a pop-up reminder of events scheduled using the MS Office Calendar
    XCalc Microsoft Windowswincalc.exeAdded by an unidentied WORM or TROJAN!
    XCALC32CALC32.EXEAdded by the SPYBOT-EC WORM!
    NCalendar 200X Remindercalendar.exeCalendar 200X - shows holidays, reminders of various anniversaries,tasks etc
    UCalendarscopecs.exeCalendarscope calendar software
    Xcalkcalk.exeAdded by the STARTPA-FH TROJAN!
    XCall Function System32sddriver.exeAdded by a variant of the SDBOT TROJAN!
    XCall32Call32.exeAdded by the SPAMMIT-H TROJAN!
    YCallBumpingcbpopw.exeRelated to the Gazel 128 PCI ISDN adapter. Required if you use it
    UCallCenter Main ApplicationV3calmcp.exe"V3 Inc. CallCenter is a free 32-bit, integrated fax, voicemail and data communications application with a simple to use interface providing fax send and receive functionality, basic (single mailbox) answering machine capability, and sophistcated data communications." Main application
    UCallCenter Printer InterfaceV3faxecp.exe"V3 Inc. CallCenter is a free 32-bit, integrated fax, voicemail and data communications application with a simple to use interface providing fax send and receive functionality, basic (single mailbox) answering machine capability, and sophistcated data communications." Fax printer
    NCallControlftctrl32.exeFaxTalk Messenger Pro is a Windows TAPI based 32-bit application. When installed, the software automatically loads FaxTalk CallControl when you start Windows. When FaxTalk CallControl is running, any TAPI compliant application can request to use the modem from Windows
    NCamCheckCamCheck.exeNuCam camera software related
    UCamenoCameno.exeCameno is a program which brings tabbed windows to MSN Messenger 6.0 and above
    UCamera DetectorCAMDET~*.EXEACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically
    UCamera DetectorCamdetect.exeACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically
    UCamera DetectorDEVDET~*.EXEACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically
    NCamio Viewer xIXApplet.exeImage viewing program that comes with digital cameras. Shows pictures that are in the camera before downloading them. "x" in the name is the version
    ?CamMonitorhpqcmon.exeFrom HP and related to digital imaging
    NCanadaCanada.exeKnown to be a dialler - but is it maliscous or clean?
    UCanarycanary-std.exeCanary keystroke logger/monitoring program - remove unless you installed it yourself!
    Xcandycommand32.exeAdded by the RBOT-LV WORM!
    XcandynetTaskmsg.exeAdded by the RBOT-NA WORM!
    UCanon MultiPASS Status Monitormonitr32.exeCannon Multi-Pass status monitor - your choice
    ?Canon PC1200 iC D600 iR1200G Status WindowCAPM1LAK.EXECannon printer related - is it required in startup?
    NCanon Printer Monitor BJCxxxCjstlst.exeTrayicon for Canon printer. xxx denotes model. Available via Start -> Programs
    UCanonMyPrinterBJMyPrt.exePrinter software for Canon Bubblejet printers
    UCanonSolutionMenuCNSLMAIN.exeCanon's Solution Menu dialog box leads you quickly toward documentation, utilities, and help files
    ?CAP3ONCAP3ONN.EXECanon driver, purpose unknown. Is it required in startup?
    Ycapfasemcapfasem.exeCA Personal Firewall - part of the CA Internet Security Suite
    NCapfaxcapfax.exePhoneTools fax software
    Ucapfupgradecapfupgrade.exeCA Personal Firewall - part of the CA Internet Security Suite
    UCAPingCAPing.exeCitibank Citianywhere software
    YCaponCapon.exeCanon printer driver
    YCaponCaponn.exeCanon printer driver
    XCaptionMgr32crssr.exeAdded by the ZAR.A WORM!
    Xcapturecapture.exeAdded by the THEEF-B TROJAN!
    NCapture Express 2000capexp.exeCapture Express - screen capture utility
    NCarbonite BackupCarboniteUI.exe"Carbonite?s online backup service starts automatically and works quietly and continuously in the background protecting your data"
    NCard MonitorREGCNT09.exeFor the USB connection on a Panasonic PV-DV701 Digital Camcorder. Available via Start -> Programs
    XCare20Care20.exeTopMoxie adware
    UCare2GTUCare2GTU.exeCare2 Green Thumbs-Up (from the Care2 site). Every online purchase helps environmental causes; tells you how eco-friendly a company really is, thanks to over 200 company profiles from Coop America. Saves 1 square foot of rainforest every day you use it. If it works and you like it, keep it
    Ucarpservcarpserv.exeAssociated with Zoltrix and Conexant modems - enables the internal modem speaker, allowing you to listen to the dial-up sounds for example
    XCARPserverCARPserver.exeAdded by the BANKER-AN TROJAN!
    UCARPservicecarpserv.exeAssociated with Zoltrix and Conexant modems - enables the internal modem speaker, allowing you to listen to the dial-up sounds for example
    Xcartao[path to file]Added by the DLOADER-QD TROJAN!
    Xcartaoconflicted.exeAdded by the DADOBRA-DV TROJAN!
    Xcartaokilling.exeAdded by the DLOADER-QN TROJAN!
    XCAS Clientcasclient.exeCasinoClient adware
    XCas2Stubcas2stub.exeCasinoClient adware
    UCasAgntCasAgnt.exeProgram by Extended Systems which allows you to sync your Casio PDA with your PC
    XCasdvqwabmqnzkg.exeAdded by the RANDEX.BE WORM!
    XcaseyvideoCaseyVideo.exeMalware causing p0rn popups
    Xcaseyvideocaseyvideo[*].exe [* = digit]Malware causing p0rn popups
    XCashBackcashback.exePart of eXact Advertising Software, consisting of "CashBack by BargainBuddy", BullsEye Network and NaviSearch
    XCashFiestaCashfiesta.exeCASHFIESTA.A pay-per-surf adware
    NCashsurfers Cashbar NavigatorCashbar.ExeCashsurfers CashBar Navigator - "The CashBar rotates banner advertisements once per minute and provides you with access to up to date special offers and deals"
    XCashToolbarCD_Load.exeCashToolbar Downloader-MY adware
    XCashToolbarsvchost.exeCashToolbar Downloader-MY adware. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
    XCasino Royalejamesbond.exeAdded by the RBOT-FZO WORM!
    XCassandra[10 to 14 random char]THD.EXEAdded by the KREPPER-AI TROJAN!
    XCassandracassandra.exeSuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as a variant of the KREPPER TROJAN!
    XCasStubcasstub.exeAdded by the CASS-A TROJAN!
    XCatalyst Control Centreatixvdm.exeAdded by the RBOT.DMW TROJAN!
    Xcatsrvcatsrv.exeAdded by the PAPLOK TROJAN!
    YCAVRIDCAVRID.exeeTrust? EZ Antivirus Real Time Infection Report from Computer Associates
    YCAVSCAVS.exeCheyenne (now eTrust) antivirus
    XCAZNOVASCAZNOVAS.exeAdded by the CAZNO TROJAN!
    XCBACK.EXECBACK.EXEAdded by the PENTA-A TROJAN!
    UCBWAttnCBWAttn.exeRequired for Bitware to answer incoming faxes, can cause sleep mode problems
    UCBWHostCBWHost.exeRequired for Bitware to answer incoming faxes, can cause sleep mode problems
    ?CBWUserCBWDial.exeAssociated with Bitware that integrates fax, voice, pager, and data communications on your desktop
    XCC2KUIcomet.exeComet Cursor adware
    XCcaoregedit.exeProbably a variant of MediaTickets adware. Note - this is not the valid Windows registry editor which resides in Windows or Winnt and will not figure in Msconfig/Startup! This version resides in a "mduu" subfolder, which may change
    YccAppccApp.exePart of Norton AntiVirus. Auto-protect and E-mail check will not function without this
    XccApp[random filename]Added by the OBSORB TROJAN! Note the random filename compared to the valid Norton AntiVirus
    XccAppWMADZ.EXEAdded by the RBOT-LJ WORM!
    XccApp.EXEAdded by the RBOT-LJ WORM!
    XccAppgcasServ.exeAdded by a variant of the RBOT WORM! Do not confuse with the Microsoft AntiSpyware executable of the same name
    XccApprsvcrhost.exeAdded by the TACTSLAY.A TROJAN!
    XccApprexpIorer.exeAdded by the TACTSLAY.A TROJAN!
    XccApproutIook.exeAdded by the TACTSLAY.A TROJAN!
    XccApprsvcshost.exeAdded by the TACTSLAY.A TROJAN!
    XccAppsservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
    XccAppswinlogon.exeAdded by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
    XccAppsN/AAdded by the KANGAROO-A TROJAN!
    XccAppsccApps.exeAdded by the KANGAROO-B WORM!
    XccctpHistoryJMTi.exeAdded by the GANBATE.A WORM!
    UCCD ManagerDDS.EXEProject Labs Century CD manager for their CD/DVD storage device
    NCcdecoderundll32.exe streamci, StreamingDeviceSetupPart of the closed caption decdoder/MS VBI codec. Should only run once
    YCCDoctorLogonTestingccdoctor.exeChecks your system to make sure it's configured properly for running IBM Rational ClearCase, a source code management tool. ClearCase is fairly sophisticated so there are a lot of system-related things that can cause it grief. If you run ClearCase you should not disable this as it provides a valuable service, but technically it isn't required to use the ClearCase product
    YccenterCCenter.exeRAV AntiVirus
    YCcEvtMgrccEvtMgr.exePart of Norton AntiVirus 2003. Event manager for scheduling weekly scans and or automatic virus updates. Used to start automatically via "ccApp" and was not required as a seperate entry but a recent update changed this
    XccEvtMrg.execcEvtMrg.exeAdded by the RBOT.GZ WORM!
    XccExecutebootcfg1.exeAdded by the NEMSI-B VIRUS!
    XccHelpccHelp.hta"Searchq" adware
    Uccleanerccleaner.exeCCleaner - removes unused files from your system
    XccpAppscsrss.exeAdded by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
    XccpAppslsass.exeAdded by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder
    UccProxyCCPROXY.EXEPart of Norton Internet Security, proxy server that is used to support the parental controls. If you turn parental controls off at user level the process is not loaded. Reported to cause excessive CPU usage
    XccPrxy.execcPrxy.exeAdded by the SHIPUP-H WORM!
    YCcPxySvcCCPXYSVC.exePart of Norton's AntiVirus 2003, Internet Security and Firewall products. E-mail proxy service - required for E-mail scanning and the firewall
    Xccregexplorer.exeAdded by the ZCREW TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System subfolder
    YCcRegVfyccRegVfy.exePart of Norton AntiVirus 2003. "ccRegVfy.exe is responsible for checking the integrity of the NAV registry entries to make sure that the information has not been changed by a malicious threat or a hack"
    XccRegVfYexpIorer.exeAdded by the TACTSLAY.A TROJAN!
    XccRegVfYsvcrhost.exeAdded by the TACTSLAY.A TROJAN!
    XccRegVfYsvcshost.exeAdded by the TACTSLAY.A TROJAN!
    XccRegVfYoutIook.exeAdded by the TACTSLAY.A TROJAN!
    Xccrssmsdtc.exeAdded by the STAP-C WORM!
    YccSetMgrccSetMgr.exePart of Norton AntiVirus 2004. What does it do?
    XccSvcHst.execcSvcHst.exeAdded by the SDBOT-DIW WORM!
    Xccsvit.execcsvit.exeAdded by the STARTPA-HP TROJAN!
    Ucctraycctray.exePart of CA Internet Security Suite
    XccUpdateccUpdate.exeAdded by the AGOBOT.YS WORM!
    UccUpdMgrccUpdMgr.exeIn Loco Parentis remote surveillance software. Uninstall this software unless you put it there yourself!
    UCCUTRAYICONCCU_TrayIcon.exeRelated to Traybar Launcher from Intel Corporation belonging to Intel(R) Viiv?
    UccWasheraolwasher.exeWebroot Cache & Cookie Washer - cleaning browser tracks, including cache, cookies, history, mail trash, drop-down address bar, auto-complete forms and downloaded program files for IE, Netscape and AOL
    UCCWC7aac.exeMoleculesoft Cache, Cookie & Windows Cleaner. No longer supported but available for free
    UCCWC7Iidxl.exeMoleculesoft Cache, Cookie & Windows Cleaner. No longer supported but available for free
    UCCWC7sstealth.exeMoleculesoft Cache, Cookie & Windows Cleaner. No longer supported but available for free
    YCCWinTraywintmr.exeSystem Tray access to Child Control parental control software by Salfield
    NCD Storage Mastercdstorager.exeCD Storage Master - a program designed to catalog CD information, boasts a number of handy features for organizing your collection
    Xcd1cd1.exePremium rate adult content dialler
    NCDANTSRVCDANTSRV.exeC-Dilla License Management software. Used for any program that uses C-dilla Protection, example: 3D Studio Max 4.x. It loads as a service automatically but is not needed unless you run said program. Can be started and stopped manually
    XCdcompatCdcompat.exeAdded by the GEMA TROJAN!
    Xcddrv32cddrv32.exeAdded by a variant of the CRYPTER.C TROJAN!
    NCDInterceptorcdi.exeCD indexer for measuring the speed of CD players
    Ycdloadercdloader2.exeFrom MagicJack - "A softphone device that allows you to attach an analog phone into the PC so you can have a traditional-style phone system in your house without any monthly charge"
    XCdnCtrcdnup.exeCNNIC Update pest
    XCDriverwindrv.exeAdded by the DELF.WG TROJAN!
    XCDriversvchost.exeAdded by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
    XCdrom Controllercdromcntrl.exeAdded by the BATTRY-A TROJAN!
    Xcdscds.exeAdded by the SPYMON TROJAN!
    XCDSpeed.exeCDSpeed.exeDetected by Kaspersky as the IRCBOT.AEX TROJAN!
    NCDTrayCDTray.exeOn HP PCs, this is the small CD icon next to the time
    UCeEKEYCeEKey.exeHot Key utility included on Toshiba Satellite laptops
    UCeEPOWERcepmtray.exeToshiba's Power Management Utility - allows the user to setup different profiles for both AC power and Battery Power on laptops. Contols CPU speed, Monitor Shut Off, Hard Drive Shut-Off, Monitor Brightness, System Stand-by and System Hibernate times
    ?CeicCeic.exe??
    XCekirge[path to worm]Added by the KERGEZ.A WORM!
    Xcenter[random name]32.exeAdded by the BOFRA.A WORM!
    XCentralProcessortaskimgr.exeAdded by the BANCOS.J TROJAN!
    ?CEPAwsot.exe??
    UCertificateRegistrationSafeSignCertReg.exeSafeSign Certificate Registration Utility for Microsoft Crypto applications
    UCertRegcertreg.exeRelated to Gemplus Card Reader
    YCertStoreInitCertStoreInitAladdin eToken authentication and password management
    NCesarFTP FTP Serverserver.exeCesarFTPd - FTP server
    Xcesmain.dllRundll32.exe [path] cmail.dll, Rundll32CnsMin (Chinese Keywords) hijacker related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
    XCEventMgrCell.exeAdded by the BIFROSE-AK TROJAN!
    NCFDCFD.exeBroadJump Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programs
    XCFDStartWinMuschi.exeWINMUSCHI dialler
    Xcfgboostcfgboot.exeAdded by an unidentified WORM or TROJAN!
    Ycfgintprcfgintpr.exeConfiguration Interpreter - part of Tiny Personal Firewall V4
    Xcfgmgr51RunDLL32.EXE cfgmgr51.dll, DllRunBookedSpace parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "cfgmgr51.dll" file is located in the Winnt or Windows folder
    Xcfgmgr52RunDLL32.EXE cfgmgr52.dll, DllRunBookedSpace parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "cfgmgr52.dll" file is located in the Winnt or Windows folder
    Ncfgwizcfgwiz.exeIntroduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it
    ?cFosDNTcFosDNT.execFos DSL Modem driver related. What does it do and is it required?
    ?cFosInst_Checkcfosinst.execFos DSL Modem driver related. What does it do and is it required?
    UcFosSpeedcFosSpeed.execFos Software Internet acceleration program related. Note - may be necessary for the software to work properly
    UCFSServ.exeCFSServ.exeBelongs to Toshiba's configfree utility and searches for Wireless Devices
    Xcftmonsfcmonit.exeAdded by a variant of the AGENT.ERG TROJAN!
    Xcftmon32taskmgr*.exe [* = number]Added by the SOWSAT.C and SOWSAT.J WORMS!
    Xcfycfy.exeSurfenhance.com SearchForIt adware variant
    XCGI Firewall ScriptCGIAGENT.EXEAdded by the BROPIA-U WORM!
    UCGServercgserver.exeAssociated with an Eicon Networks ISDN or ADSL modem. Call Guard Server (CGserver) watches your modem and blocks incoming or outgoing calls. You need cgard.exe (from Startmenu) to configure cgserver with rules and telephone numbers. Good against unwanted dialer programs
    XCgtask Servicescgtask.exeAdded by the LALA.B TROJAN!
    XCgywincgywin32.exeAdded by the RBOT-AEI WORM!
    UChamClockChamClock.exeChameleon Clock - system tray clock replacement
    Xchange-me-nowmsgfix1.exeAdded by the SDBOT.ZD WORM!
    UChangeICONSPMSMON.EXECard reader related program. Note - may cause problems with My Computer loading at startup. Disabling through MsConfig seems to solve the problem
    ?ChangeLineschngline.exe??
    YCharter High-Speed Security Suitefspex.exeCharter High-Speed Security Suite - security software in collaboration with F-Secure
    NChatangoChatango.exeChatango - "allows people to be connected in real time through their Web browsers. Include your Chatango contact link or button when you create eBay auctions, blogs, personal websites, Friendster profiles, and your visitors will be able to contact you instantly, without downloading anything, or registering. Alo use it to send email to your friends, allowing them to respond to you in real time!." The 'MessageCatcher' icon in the System Tray notifies you when you get a message. When you get a message, a little alert pops up, which you can click on and start chatting immediately
    UChatStatChatStat.exeChatStat from ChatStat Technologies, Inc. Provides live chat assistance in up to 16 languages allows your operators to be more productive
    NChcenterchcenter.exeIMSI HiJaak - "the easiest way to convert, capture, and manage all your graphic files"
    XChckupNetverchk.exeCovert Sys Exec malware variant
    Xchcp.exechcp.exeDetected by Kaspersky as the SDBOT.BMH WORM! See here
    Xche32che.ocx.vbsAdded by the ADENU-B VIRUS!
    XCheatleGigaByte.exeAdded by the SHODI.B VIRUS!
    XCheckCheck.exeAdded by the VB-DRN WORM!
    NCheck for One Touch Updatewiseupdt.exeChecks for updates for Visioneer OneTouch scanners
    NCheck for TWS UpdatesWiseUpdt.exeInteractive Brokers - check for update to their standalone Java-based trading platform
    UCheck Messengercmesseng.exeCheck Messenger from Qchex.com - program that helps you manage the activity of your Qchex account. Qchex appear to be no longer in buisness
    UCheck&GetCheck&Get.exeCheck&Get from ActiveURLs. Manages your browser bookmarks and favorites. Monitors Web sites for changes and updates, captures and highlights the changed contents
    NCheckCustomWorksUpdateCheckCWupdate.exeUpdate checker, part of CustomWorks - "customize any embroidery designs to design your own unique creations"
    UCheckDialerChkDial.exeAdded by the CheckDialer modem connection monitoring tool
    XCheckdiskmscas.exeAdded by the VAGON-A TROJAN!
    XCheckFaultKernelmswdm.exeAdded by the SMALL-CSK TROJAN!
    UCheckItToolBox.exeCheckIt Toolbox from WinCheckIt Diagnostic Software. Toolbox automatically backs up critical system files (such as .ini files and the Windows Registry), and performs a check on various system parameters at intervals you specify
    UCheckIt 86CheckIt86.exeCheckIt 86 popup blocker
    YCheckMsgPlusMsgPlusH.dll, VerifyInstallationAdded by MSN Messenger Plus, a third party extension to MSN Messenger. This is the auto-update feature - see here for more info.
    Xcheckrunelite***32.exe [* = random char]EliteBar adware
    Xcheckrunelitelsj32.exeAdded by the MULTIDR-ER TROJAN!
    XCheckScan32regload16.exeAdded by the AEBOT.K WORM!
    ?checktimect.exeFound in the HPSelectFrontend directory on a HP machine. What is it's purpose and is it required?
    YCheckVCRIOMagic.exeDriver for the I/OMagic Personal Video Recorder (DR-PCTV100)
    XCheckWinPerfperfinfo.exeAdded by a variant of the IRCBOT TROJAN!
    UCherryKeyManKeyMan.exeMultimedia keyboard manager for the Cherry keyboard series. Only required if you use any of the special keys
    XchiCkiechiCkie.exeAdded by the CHIKO WORM!
    UChicoSyswebtmr.exeChild Control parental control software
    UChikkaDefaultChikkaLauncher.exe Chikka PC text messanger and IM client
    Xchina11msnCHINA11MSN.EXEAdded by the ENVID.O WORM!
    UChineseStarcstar.exeChinese language support software
    UCHIPDRIVEPinManagersokscmpn.exeChipDrive Smartcard software
    UCHIPDRIVESmartcardManagerSCMgr.exeChipDrive Smartcard software
    NCHKADMINCHKADMIN.EXECompaq Network Management System. When running, it places an icon in the system tray titled "Intelligent Manageability"
    XChkDiskchk_disk.exeAdded by an unidentified WORM or TROJAN!
    Xchkdrviemon.exeDetected by Symantec as the ADCLICKER TROJAN!
    Xchkdskautoexec.batAdded by the ANPES WORM!
    UChkMailChkMail.exeMail-checking program supplied with Acer notebooks
    UChoiceMailCHOICEMAIL.EXEChoiceMail from DigiPortal Software. Block spam with an Email firewall
    XChokeChoke.exe-blahhAdded by the CHOKE WORM!
    Xchoperunlli32.exeAdded by the QQPASS-U TROJAN!
    Xchostsvchostsv.exeAdded by the BANPAES.C TROJAN!
    UCHotKeymhotkey.exeEnables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol+, vol-, mute, etc. Only required for extended features
    UCHotKeyMK9805.EXEEnables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol+, vol-, mute, etc. Only required for extended features
    UCHotKeyzHotkey.exeEnables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol , vol-, mute, etc. Only required for extended features
    NChristmas Music PlayerTTEST6.EXE"Christmas Music Player brings the music of the Christmas Holiday to your desktop"
    ?ChromeMarkkeysh.exeRelated to this. Don't know what keysh.exe does though and if it's required
    ?ChronitelInitTVCHTVINIT.EXE??
    Uchronochrono.exeChronograph is a simple utility that synchronizes internal computer clock to the atomic time. Chronograph automatically maintains correct time using atomic clock servers of the National Institute of Standards and Technology (NIST)." Shows seconds and shows the date without having to hover the mouse. Shows a calendar when hovered over
    Xci1gntci1gnt.exeDetected by Kaspersky as the AGENT.DHU TROJAN!
    XCiaBackdoormsldr.comAdded by a VIRUS!
    Xcihost.execihost.exeAdded by the LINST TROJAN!
    NCIJxP2PSERVERCIJxP2PS.EXECompaq printer utility which is required in order to make the printer work correctly - "x" depends upon the model, ie, for IJ300 x=3, for IJ700 x=7
    YCingular Communication ManagerCingularCCM.exeCingular Communication Manager - now taken over by AT&T. "provides a robust set of wireless communication tools for businesses and individuals. With wireless access to email, the Internet, business applications and corporate intranets, mobile users can be more productive while they're out of the office"
    XCinnabd Prompt32CmdPrompt32.pifAdded by the ASSIRAL-B WORM!
    NCIOche7e1~1.exeChatItOut webcam chat program
    XCirebonPunyaXXrocks.exeAdded by the BHARAT.A WORM!
    UCisco Systems VPN Clientipsecdialer.exeCisco VPN Client - lets local users gain Administrator privileges on the operating system
    NCisco Systems VPN Clientvpngui.exeSets up IPSec communications for Cisco's VPN Client
    NCISrvr ProgramCISRVR.EXERelated to internet setup on Compaq PC's
    XCissiCissi.exeAdded by the CISSI.A WORM!
    UCitiUCSCitiUCS.exeCitibank Virtual Account Numbers - "With this free service for Citi cardmembers, you never have to give out your real credit card number online"
    NCitiVANCitiVAN.exeOption from Citibank to change a credit card number in a random fashion for each purchase. The number will only be used once and never again
    Xcjbcjb.exeAdded by and unidentified WORM or TROJAN! See here
    XCJETCJet.exeAdded by the Adware.FFToolBar adware toolbar
    YCjstcomCjstcom.exeCanon printer BJ status language monitor
    YClamWinClamTray.exeClamWin antivirus
    XClassesint1.exe"Switch" premium rate adult content dialler variant
    XClassesintl.exe"Switch" premium rate adult content dialler variant
    XClassesrun_21.exe"Switch" premium rate adult content dialler variant
    XClassessrv.exe"Switch" premium rate adult content dialler variant
    XClassessrv2.exe"Switch" premium rate adult content dialler variant
    XClassesMSTAR2.EXE"Switch" premium rate adult content dialler variant
    XClassesmstart.exe"Switch" premium rate adult content dialler variant
    Xclcbt.execlcbt.exeAdded by the AGENT.CBA TROJAN!
    Xclcl3clcl3.exeAdded by the AGENT.ES TROJAN!
    Xclcl7clcl7.exeAdded by a variant of the Covert Sys Exec TROJAN!
    UCLCLSetCLCL.exeCLCL clipboard caching utility
    NClean Access AgentCCAAgent.exeCisco Clean Access Agent from Cisco Systems, Inc
    XClean upservice.exeAdded by the AGENT-FPY TROJAN!
    ?CleanEasyImgcleanall.exe??
    ?CleanRegPathCleanReg.exeApparently Annex A ADSL modem related. What does it do and is it required?
    UCleanSweep Smart Sweep- Internet SweepCsinsm32.exeAutomatic logging of installs from Norton CleanSweep - available via Start -> Programs
    NCleanSweep Useage WatchCSUSEM32.EXEQuarterdeck/Norton CleanSweep component - tracks how often you use files and alerts you to files that have not been used for a specified period of time
    UCleanTempCLEANT~1.EXEBCleanTemp - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory
    UCleanTempCleanTemp.exeCleanTemp - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory
    NCleanupONICTASK.EXEInternet Cleanup from Allume Systems (used to be by OnTrack) - cleans up tracks left by browsing the internet
    YCleanUpmcappins.exeUsed by McAfee Virusscan to perform product updates. When updates are available the program will download and install them automatically. Recommended to leave enabled
    ?CleanupProgramcleanup.exeIn a C:Sonysys folder - Sony Vaio related?
    Xclean_serviceclean_service.cmdAdded by the REFAZ WORM!
    UCleverKeysCK.exeCleverKeys - "is free software that provides instant access to definitions at Dictionary.com, synonyms at Thesaurus.com, facts at Reference.com and more ? from almost all Windows programs, including word processors, Web browsers and most e-mail programs"
    Xclfmonclfmon.exeAdded by the TACTSLAY.E TROJAN!
    Xclfmonnvsvca32.exeAdded by the TACTSLAY.E TROJAN!
    Xclfmon.execlfmon.exeAdded by the AGENT-BJ TROJAN!
    NClick Radio Tunerclickr~1.exeClickRadio - subscription service playing radio music via the internet
    NClick Tray CalendarClickT~1.EXEClickTray Calendar - shows holidays, reminders of various anniversaries,tasks etc
    NClickMeClickMe.exeClickM "JOKE" program
    UClickoffClickoff.exeClickoff automatically dismisses annoying dialog boxes
    XClickTheButtonCTB.EXEClickTheButton Downloader-MY adware
    XClickTheButtoncsrss.exeClickTheButton Downloader-MY adware! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!
    XClickTheButtonMSCStat.exeClickTheButton Downloader-MY adware
    XCLICONFGCLICONFG.EXEAdded by the OPASERV.T WORM!
    UClient Access API Daemoncwbappcd.exeIBM iSeries Client Access, see here
    NClient Access Check Versioncwbckver.exePart of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Checks the software version on your PC to that of the iSeries it is connected to. Not required - and can be turned off in the Client Access properties. It's a waste of resources
    ?Client Access Express Welcomecwbwlwiz.exeWelcome wizard launcher - Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. What does it do and is it required?
    NClient Access Help Updatecwbinhlp.exeClient Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. It only updates the help files on your PC to match the level of the attached iSeries
    NClient Access ServiceCwbSvStr.ExePart of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Useful if you are going to access the iSeries through Windows Explorer to move files back and forth between Windows folders and iSeries folders. This is a tool that is only used by Client Access administrators (usually) so it is not required - a waste of resources
    UClient Access Taskbarcwbuitsk.exeIBM iSeries Client Access taskbar, see here
    XClient Agentipxwping.exeAdded by the PPDOOR-N TROJAN!
    XClient Agentphotes.exeAdded by the PPDOOR-P TROJAN!
    XClient Agent[path to file]Added by the PPDOOR-J TROJAN!
    ?Client agent for ARCserveW95AGENT.EXEPart of Brightstor ARCserve Backup from Computer Associates. What does it do and is it required?
    XClient for Microsoft Networksmsclient32.exeAdded by the SDBOT-BXQ WORM!
    XClient Server Control Process[path to trojan]Added by the AGENT-HR TROJAN!
    XClient Server Run Time Proccesscsrsrv.exeAdded by a variant of the SDBOT WORM!
    XClient Server Runtime[path to worm]Added by the POEBOT-KR WORM!
    XClient Server Runtime Processcsrsss.exeAdded by the SDBOT-LD WORM!
    XClient Server Runtime Processcsrs.exeAdded by the LINKBOT.M WORM!
    XClient Server Runtime Processsmmss.exeBackdoor TROJAN! Possible SDBOT-GEN variant
    XClient Updatewup.exeAdded by a variant of the OPANKI-A WORM!
    XClientMan1mscman.exeClientMan parasite variant
    NClik Status Monitortoolsclickstat.exePart of Iomega Tools to let you know whether an Iomega PocketZip (nee Clik) removable drive cartridge is installed
    Xclipboard.execlipboard.exeAdded by an unidentified WORM or TROJAN!
    NClipbook ServiceClipsrv.exeSupports Windows XP ClipBook Viewer, which allows pages to be seen by remote ClipBooks
    NClipMate5xClipMt5x.exeClip Mate 5.x by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs
    NClipmate6CLIPMT60.EXEClip Mate 6 by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs
    NClipMate7ClipMate.exeClip Mate 7 by Thornsoft - utility that allows you to store more than one item in the clipboard
    NClipomaticClipomatic.exeMike Lin's Clipomatic is a clipboard cache program - it remembers what was copied to the clipboard even after new data is copied, and allows you to retrieve the old data
    NClipsrvClipsrv.exeSupports Windows XP ClipBook Viewer, which allows pages to be seen by remote ClipBooks
    XClipSrvclipserv.exeAdded by the SDBOT-AAV and SDBOT-AFE WORMS!
    XClipSrvCLIPBRD3D.EXEAdded by the MOFEI-D WORM!
    NClipTrakClipTrak.exeClipTrak - clipboard extender
    NClipTrakkerClipTrakker.exeCliptrakker - clipboard extender
    NCLISTARTCLIStart.exePuts the ATI Catalyst? Control Center Icon/Shortcut on the System Tray - available via Start -> Programs
    Xclkhost[path to trojan]Added by the WIXUD-B TROJAN!
    UCLMFrontPanelclmpanel.exeSystem tray status/display/configuration utility for a number of modems. Can be disabled by right-clicking on the tray icon. If disabled, connection status is lost
    ?clnwallrundll.exe setupx.dll, InstallHinfSection ..delwall.inf??
    Xclock[various filenames]LiveChat Adware - known file names include: mssetup.exe, kstatus.exe, spoolsv.exe, sptsupd.exe, osk.exe, msswchx.exe, netdde.exe, msbkup.exe
    XClock Manageramsngr.exeAdded by the SDBOT-XM TROJAN!
    XClockSyncSync.exeClockSync - synchronizes your system clock with an internet time server. It's by WhenU, the makers of the Save Now spyware, and they're usually seen in tandem, so it's advised to replace it with one of may spyware free alternatives available
    UClockWiseCLOCKWISE.EXEClockWise - produced by R J Software - a time utility. It is a schedueler not only for dates, but you can choose it to run programs at any time. It also updates the time by connecting to an atomic clock server. This is a spyware-free alternative to ClockSync
    UClocXClocX.exeClocX - places a clock on the desktop that can be moved and then changed into a calendar plus you can set alarms etc?
    UCloneCDCloneCDTray.exeSystem tray for the now discontinued CloneCD. The only useful option is "Hide CDR Media" only available via this tray. Has additional unknown functions in later versions
    UCloneCDElbyCDFLElbyCheck.exeFrom Elaborate Bytes who make CloneCD - monitors the installed filters of CD-ROMs/DVD-ROMs. Note - under Win2K removing this from startup causes the CD drive in the computer to not be recognized in the OS and after rechecking it prompts that the driver has been corrupted and asks you to restart the computer to fix it
    UCloneCDTrayCloneCDTray.exeSystem tray for the now discontinued CloneCD. The only useful option is "Hide CDR Media" only available via this tray. Has additional unknown functions in later versions
    ?Clotusorgreg0prtStart.exe [path] Orgprt.exeIBM Lotus SmartSuite related. In a LotusOrgReg folder. Unclear what exactly it does?
    XClremmdc.exeAdded by the PURSCAN-AI TROJAN!
    XClrSchLoader[path to file]ClearSearch adware
    XCLSIDcom.exeAdult content dialler
    XCLSIDdll.exeAdult content dialler
    XCLSIDmsgplus.exeAdult content dialler
    XCLSIDplugin.exeAdult content dialler
    XCLSIDsed.exeAdult content dialler
    XCLSIDmsgplus.exePremium rate adult content dialer. Note - this is NOT the MSN Messenger 'MessengerPlus' extension
    XCLSRSSLSACS.EXEAdded by the SILLYFDC-X WORM!
    ?CM-SmWizardSmWizard.exeSmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required?
    Ucmacma.exeDeskSite CMA siftware - "retrieves new content from the DeskSite Data Center"
    XCMAPPcmappclient.exeCasClient adware - also detected as the CMAPP TROJAN!
    NCmaudioRundll32 cmicnfg.cpl, CMICtrlWndSystem tray control panel for C-Media based soundcards - often included on popular motherboards with in-built audio. Available via Start -> Settings -> Control Panel
    XCmdcmd32.exeAdded by the TANKED WORM!
    Xcmd32configs.exeHijacker, also detected as the QURL-2 TROJAN!
    Xcmd64cmd64.exeCoolWebSearch Search X parasite variant
    Xcmdbcscmdbcs.exeAdded by the LINEAG-GKW TROJAN!
    Xcmdconcmdcon.exeAdded by the CRYPTER.A TROJAN!
    Xcmdsvtsqn.dllAdded by a variant of the VUNDO TROJAN!
    XCmdShell.exeCmdShell.exeAdded by the BCKDR-QHY TROJAN!
    XCMEcme.exePart of Gator advertising spyware - see here for removal instructions. Please note that Claria Corporation no longer support GAIN-Supported software - see here
    XCmeSYSCMEsys.exePart of Gator advertising spyware - see here for removal instructions. Please note that Claria Corporation no longer support GAIN-Supported software - see here
    XCmeUPDCMEupd.exePart of Gator advertising spyware - see here for removal instructions. Please note that Claria Corporation no longer support GAIN-Supported software - see here
    XCMFibulaCMFibula.exeCASClient adware
    NCmFlywaveNameCmFlywav.exeDriver for Linksys Wireless-G Music Bridge
    ?CMGrdianCMGrdian.exeOne of the McAfee shared components. What does it do and is it required?
    XCMManCMMan.exeAdded by the CMAPP TROJAN!
    XCmmon32Syscmmon32.exeAdded by the SMALL.CL TROJAN!
    Xcmonitorstartupmon.exeSystemDoctor misleading security software - not recommended, see here
    UCmPCIaudioRunDll32 CMICNFG3.CPL, CMICtrlWndRegisters the Control Panel applet for a C-Media PCI sound card
    UCMPDPSRVCMPDPSRV.EXEPrinter Driver Plus from ViewAhead Technology (formerly DeviceGuys, Inc.). "Printer Driver Plus seamlessly integrates all the necessary components of a printer driver, plus more". Installed with some Compaq and Lexmark printers
    XCmpntDevices2.exeAdded by the TOMPAI-D TROJAN!
    XCmpntmainsv.exeAdded by the TOMPAI-C TROJAN!
    Xcmrsscmrss.exeAdded by the DELF.DU TROJAN!
    Xcmrsscrmss.exeAdded by the DLOADER-EK TROJAN!
    Xcmrss[path to trojan]Added by the DLOADER-QQ TROJAN!
    Xcmrstcmrst.exeAdded by the BANCOS.S TROJAN!
    Xcmrstcmrst.scrAdded by the DLOADER-FP TROJAN!
    Xcmsiserver.exeAdded by the DLOADER-WK TROJAN!
    UCMSETTINGSctmn.exePart of NetNanny Chat Monitor
    Xcmsoundvcpdll.exeAdded by the TCXMEDI-D downloader TROJAN!
    Xcmsoundvcsystem.exeAdded by the TCXMEDI-D downloader TROJAN!
    Xcmsssystem.exeAdded by a variant of the RBOT WORM!
    Xcmssappiexplore_.exeAdded by the BANCBAN-CQ TROJAN!
    Xcmssappiexplore.exeAdded by the BANCBAN-GF TROJAN! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
    XcmssSystemProcesscsmss.exeAdded by the AGENT-CO TROJAN!
    XcmssSystemProcessmcsmss.exeAdded by a variant of the AGENT.EI TROJAN!
    XcmssSystemProcesscsms.exeAdded by the AGENT-Y TROJAN!
    XCMSystemCMSystem.exeCASClient adware
    Xcmt101cmt101.exeAdded by a variant of the CRYPTER.C TROJAN!
    ?CmUCRRunCmUCReye.exeRelated to Medion Display Information. What does it do and is it required?
    Xcmx32cmx32.exeAdded by the GEMA.D TROJAN!
    XCn323cnfrm33.exeAdded by the MIMAIL.G WORM!
    XCn911ODBCJET.exeAdded by the BIFROSE-PR TROJAN!
    XCNBABECNBABE.EXEAppears to be spyware added by KAZAA (and maybe others) that displays pop-up ads whilst you're browsing
    Ncnetkontiki.exeKontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops
    YcnfgCavCMain.exePart of Comodo Antivirus
    XCnfrm32cnfrm.exeAdded by the MIMAIL.D WORM!
    XCnsMaxInternat.exeAdded by the POINTEX TROJAN! Note - the real internat.exe resides in %windir%system (where %windir% is the Windows directory - C:Windows or C:Winnt) whereas this version resides in %windir%
    XCnsMinRundll32.exe [path] CNSMIN.DLL, Rundll32CnsMin (Chinese Keywords) hijacker related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
    YCnwiDeviceAgentcnwida.exePart of the Canon imagePROGRAF W8400 printer management software
    YCnxAdslLCnxAdslL.exeDLink, Zoom, or Conexant modem driver
    NCnxDslTaskBarCnxDslTb.exeConnexant DSL Taskbar as used on Acess Runner and Samsung AHT-E310 ADSL modems
    UCobian Backup 8 interfacecbInterface.exe"Cobian Backup is a backup program that can be executed in 2 ways: as a normal application or as a Windows Service. The program can schedule automatic backups for files and directories locally or to FTP servers and can use compression and encryption"
    XCodeCleanCCIntro.exeCodeClean spyware remover - not recommended, see here
    UCodename Dashboarddashboard.exeCodename: Dashboard - "an application that resides at the side of your screen. Built on the Microsoft .NET Framework, it is a host for interchangeable components through which C.D. allows you to have any information you want, on your desktop, all the time"
    Xcof.updit[random filename]Added by a variant of the SDBOT WORM!
    UCognizanceTSrundll32.exe [path] AsTsVcc.dll, RegisterModuleCognizance Corp Identity And Access Management suite
    XColdlife -icmpSystray.exeAdded by the FLOOD.AV TROJAN! Note - this is not the legitimate systray.exe process
    NCollaborationHostp2phost.exePeople Near Me Microsoft? Windows? Peer-to-Peer Networking platform for Windows Vista
    Ucolorealcoloreal.exeMakes colours sharper and brighter, but will only work with coloreal capable monitors
    NColorific Control PanelHgcctl95.exeFrom E_Color. Colorific delivers accurate gamma and color temperature across your entire system - monitor to printer and digital camera to monitor
    XCOM Servicemscom32.comAdded by the BEASTY.H TROJAN!
    XCOM Servicemsynvr.comAdded by the BEASTY.G TROJAN!
    XCOM Servicemsjclh.comAdded by the BEASTY.E TROJAN!
    XCOM Servicemsdrce.comAdded by the BEASTY.I TROJAN!
    XCOM Servicemsflyx.comAdded by the BEASTDO-O TROJAN!
    XCOM+ Event SystemDRWTSN16.EXEAdded by a variant of the LOVGATE WORM!
    XCOM+ EventSystem ServicesECSERVER.EXEAdded by a variant of the SDBOT WORM!
    XCom+ Syscsrs.exeAdded by the FORBOT-BT WORM!
    XCOM+ System Applicationslsas.exeAdded by the AGOBOT.SE WORM!
    XCOM++ Systemexploier.exeAdded by a variant of the LOVGATE WORM!
    XCOM++ Systemsuchost.exeAdded by a variant of the LOVGATE WORM!
    XCOM++ Systemsvchost.exe...Added by a variant of the LOVGATE WORM!
    NCOM-IPCOMIP.EXECOM-IP Virtual Modem Driver (COM-IP Creates a Fake Serial Port that allows you to use older DOS Based Communications Programs over Telnet. Type atdt host.domain.com instead of atdt 5551212)
    Ucom.codeode.cactusspamfiltercactusspamfilter.exeCactus Spam - free easy-to-use spam blocker
    Ucom.codeode.privacymantraprivacymantra.exe"Privacy Mantra keeps your computer clean from online and offline tracks"
    UComAgentComAgent.exeComAgent - MDaemon's instant messaging client
    Xcombo.execombo.exeAdded by the CHIMO-C TROJAN!
    Xcombop.execombop.exeAdded by the BOWFEED-A TROJAN!
    XComcast Networkribiva.exeAdded by a variant of the TOADCOM.A TROJAN!
    Xcomctl32comctl32.exeAdware - detected by Kaspersky as the AGENT.AM TROJAN!
    UCOMDRV32svdhost.exeOrvell Monitoring 2003 surveillance software. Uninstall this software unless you put it there yourself. Note - asks for permission to contact the IP address of http://www.protectcom.com/
    UComm Drivercommh32.exeG Data "PC Spion". PC monitoring and surveilling software, captures all users activity on the PC, see here. Disable/remove if you didn't install it yourself!
    XCommandsystem.exeAdded by the GATECRASH.A or GATECRASH.B TROJANS!
    XCommandGotit.exeAdded by the TITOG WORM!
    XCOMMANDcommand.exeAdded by the QQPASS.E TROJAN!
    Xcommandjavaw.exeAdded by the AGOBOT-LG WORM!
    XCommand Prompt32CmdPrompt32.pifAdded by the ASSIRAL.B WORM!
    UCommand WorkStation 4cws 4.exeEFI's Command WorkStation makes "managing demanding workflows easier by centralizing job management. The software automatically identifies the Fiery servers on the network and offers customization options for displaying information" - for high-end print environments
    Xcommand32command32.exeAdded by the LINEADI-A TROJAN!
    NCommCtrcommctr.exe"Net2Phone CommCenter is the latest in Internet voice technology allowing you to place calls easily all over the world right from your PC!". Available via Start -> Programs
    YCOMMUNICATORCommunicator.exePart of Microsoft Office Communicator, which is an integrated communications client that allows information workers to communicate in real time using a range of different communication options, including instant messaging (IM), voice, and video
    UComodo FirewallCPF.exeComodo Firewall
    YCOMODO Firewall Procfp.exeComodo Firewall Pro
    UComodo Launch Pad TrayCLPTray.exeSystem Tray access to LaunchPad as bundled with Comodo's freebie offerings such as Comodo Anti-Virus. Some allege that LaunchPad is impossible-to-uninstall adware, or worse - see here
    YCOMODO Memory Firewallcmf.exe"Comodo Memory Firewall is a buffer overflow detection and prevention tool which provides the ultimate defence against one of the most serious and common attack types on the Internet - the buffer overflow attack"
    XCompanionWizardcompwiz.exeWinAntiVirus 2006 misleading virus software - not recommended, see here
    UCompaq AlerterCPQAlert.exeCompaq's Insight Manager Agent - a tool that allows for "fault, performance, and configuration management". Recommended for corporate users only. It's best removed if installed but not wanted, rather than disabled at startup. See here for more information
    NCompaq Computer Corp SCCenter ModuleSCCENTER.EXEFor Compaq PC's. Part of Backweb
    ?Compaq Computer SecurityRundll32.exe SECURE32.CPL, Service??
    NCompaq ConnectionsCOMPAQ~1.EXESee here - "messaging service that automatically sends you support information, tips, ideas, and special offers from HP and our partners, especially designed for HP and Compaq desktop computer owners"
    NCompaq ConnectionsBackWeb-1940576.exeSee here - "messaging service that automatically sends you support information, tips, ideas, and special offers from HP and our partners, especially designed for HP and Compaq desktop computer owners". * can be any digit
    NCompaq ConnectionsCompaq Connections.exeSee here - "messaging service that automatically sends you support information, tips, ideas, and special offers from HP and our partners, especially designed for HP and Compaq desktop computer owners"
    NCompaq DMIcpqdmi.exeCompaq version of the Desktop Management Interface
    XCompaq DriversF1rewalls.exeAdded by the SDBOT-WD WORM!
    NCompaq Internet Setupinetwizard.exeFor Compaq PC's. Runs Compaq internet setup wizard and offers you to signup from ISP list
    XCompaq Jes Driverswinjes.exeAdded by the SDBOT-XR WORM!
    UCompaq Knowledge Centersilent.exe & matcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file while silent.exe executes matcli.exe quietly in the background. Compaq Knowledge Center is required to run with the Help and Support program. If you uncheck Compaq Knowledge Center and and then run help and Support it will add another Compaq Knowledge Center in the startup menu. If you remove the Compaq Knowledge Center in the add/remove program some help menus in help and support will not be available like Fix my Presario, Preference, and Contact Technical Support". You decide
    NCompaq Message ServerCOMPAQ-RBA.EXEApplies to the CPQBootPerfDB entry as well. These files generate some kind of server or servlet that attempts to connect with Compaq online. They are like Trojans, but fairly harmless. They send information on the "Compaq Advisor/Compaq Message Screener" application that comes with every Compaq computer and provide feedback on how computer users use the Message Advisor. These messages appear occasionally and instruct and advise users on their computer and its use. They generally attempt to get you (these messages) to connect to Compaq's website. They may be safely disabled via (1) MSCONFIG or (2) Start -> Programs -> Compaq Advisor -> Advisor Settings under the "advanced" tab. Not required and can cause problems
    UCompaq PK Daemoncpqkl.exeFor Compaq laptops for programming user configurable keys. Not required unless you use them
    XCompaq Print Faxcpqa1000.exeAdded by the SDBOT.BCV WORM! Please take note of the difference between the legitimate Compaq Fax Utility Name (A1000 Settings Utility) and the name (Compaq Print Fax) used by this worm
    XCompaq Service Driverssysteminfos.exeAdded by the SDBOT-XC WORM!
    XCompaq Service Driverscompq.exeAdded by a variant of the SDBOT WORM!
    XCompaq Service Driversnavapqwa.exeAdded by the SDBOT.BBQ WORM!
    XCompaq Service Driversamsn.exeAdded by a variant of the SDBOT WORM!
    XCompaq Service Driverscompqs.exeAdded by a variant of the SDBOT WORM!
    XCompaq Service Driversmsnt.exeAdded by the SDBOT.CQL WORM!
    XCompaq Service DriversNtKernelSystem.exeAdded by a variant of the SDBOT WORM!
    XCompaq Service Driverswincmd.exeAdded by the RBOT.ATV WORM!
    XCompaq Service Driverswind32.exeAdded by a variant of the SDBOT WORM!
    XCompaq Service Driverswinmsn.exeAdded by a variant of the SDBOT WORM!
    XCompaq Service Driverscompaq.exeAdded by the SDBOT-AFU WORM!
    XCompaq Service Driversmsnsvc.exeAdded by the RBOT.BKT WORM!
    XCompaq Service Driversntsys32.exeAdded by the RBOT.CIW WORM!
    XCompaq Service Driverswinsvc.exeAdded by the SDBOT-AGD WORM!
    XCompaq Service Drivers 32compq32.exeAdded by a variant of the SDBOT WORM!
    XCompaq Service Drivrscopq.exeAdded by a variant of the RBOT WORM!
    XCompaq Services Driversndt32.exeAdded by the RBOT.CQZ WORM!
    XCompaq Sound Drivers For WINDOWSsounddr.exeAdded by the SDBOT-XG WORM!
    NCompaq Video CD Watcher??For Compaq PC's. MPEG viewer
    XCompaq32 Service Driversms32.exeAdded by the SDBOT.BWH WORM!
    XCompaq32 Service Driversmsconfig32.exeAdded by the SDBOT-ADC WORM!
    XCompaq32 Service Driversmsnt32.exeAdded by the RBOT.BVF WORM!
    ?CompaqHW Comp Managercpqhcm.exeRunning on a Compaq laptop - any ideas?
    NCompaqPrinTrayprintray.exePuts printer icon in the System Tray. When this option is disabled you will no longer be able to access the Control Program or Printer Driver directly from your desktop
    XCompaqs Service Drivercopypad32.exeAdded by the SDBOT.CSO WORM!
    XCompaqs Service Driverscompqs.exeAdded by a variant of the SDBOT WORM!
    NCompaqSystraycpqpscp.exeCompaq System Tray icon
    XCompatibility Service Processregsvs.exeAdded by the GAOBOT.YN WORM!
    XCompd Service Drivrscodq.exeAdded by a variant of the SDBOT WORM!
    UComproRemoteComproRemote.exeVideoMate TV tuner and capture card - remote control driver
    UComproSchedulerDTVComproSchedulerDTV.exeVideoMate TV tuner and capture card - scheduler
    XComputing Technologie Firewalllsauth.exeAdded by the SDBOT-WX WORM!
    NCOMSMDEXEcomsmd.exe3Com tray icon
    XComStartTrojan Guarder.exeTrojanGuarder misleading security software - not recommended, see here
    XComTry Web Searcherwstray.exeComtry MP3 Downloader related - spyware
    Xcomxtcomxt.exeAdded by the COMXT TROJAN!
    Xcon[path to trojan]Added by the BRAVE-A TROJAN!
    XConfidentUserSRP.exeConfidentUser misleading security software - the site's "online scanner" detected by Kaspersky antivirus as WinFixer.ba
    XConfigservice.exeAdded by the ISRAZ.B WORM!
    XConfigWinService32.exeAdded by the CRUTCHA-A TROJAN!
    XConfig LoadationiEEexplore.exeAdded by the SDBOT.H TROJAN!
    XConfig LoadatiorinI3Explorer.exeAdded by the SDBOT.H TROJAN!
    XConfig Loadersvchosl.exeAdded by the GAOBOT.P WORM!
    XConfig Loadersysldr32.exeAdded by the GAOBOT WORM!
    XConfig Loaderscvhost.exeAdded by the GAOBOT.AE or GAOBOT.AO WORMS!
    XConfig Loadersvhost.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    XConfig Loader for Microsoft Windowsmwincfg32.exeAdded by the AGOBOT.BD WORM!
    XConfig Loader2explores.exeAdded by the GAOBOT.BT WORM!
    XConfig Loadrwinsys32.exeAdded by the AGOBOT-HN WORM!
    XConfig33.exeConfig33.exeAdded by the SDBOT.T TROJAN!
    XConfiggLoadercart322.exeAdded by the GAOBOT.DJ WORM!
    UConfigSafeCFGSAFE.EXEConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions -- provides a restore function. Your choice
    UConfigSafeAUTOCHK.EXEConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions -- provides a restore function. Your choice
    NConfigServicesConfig.exePart of initial setup on a Compaq PC
    Xconfigsetupconfigsetup32.exeAdded by the AGOBOT-AFP WORM!
    XConfigurationexplorer32.exeAdded by the SDBOT-ML WORM!
    XConfiguration[filename]Added by the SDBOT-ML WORM!
    Xconfigurationapphost.exeAdded by the SDBOT-VP WORM!
    XConfigurationntsys32.exeAdded by the SDBOT-LN WORM!
    XConfiguration DefaultWuxat.exeAdded by the SPYBOT-CA WORM!
    XConfiguration FileWinset32.exeAdded by the FLUX.101 TROJAN!
    XConfiguration Loadedwupdated.exeAdded by the MOEGA or MOEGA.AG or MOEGA.AP WORMS!
    XConfiguration Loadedlssas.exeAdded by a variant of the SDBOT WORM!
    XConfiguration Loaderaim95.exeAdded by the LOADCFG or SDBOT TROJANS!
    XConfiguration Loadercmd32.exeAdded by the LOADCFG or SDBOT TROJANS!
    XConfiguration Loader syscfg32.exeAdded by the SDBOT.B TROJAN!
    XConfiguration Loaderservice5.exeAdded by the GAOBOT.AF WORM!
    ?Configuration Loaderlfass.exe??
    XConfiguration Loadersycfg34.exeAdded by the GAOBOT.AN WORM!
    XConfiguration Loaderwincrt32.exeAdded by the GAOBOT.BF WORM!
    XConfiguration Loaderwindex.exeAdded by the GAOBOT.BZ WORM!
    XConfiguration Loaderdosrun32.exeAdded by the GAOBOT.AO WORM!
    XConfiguration LoaderService.exeAdded by the GAOBOT.AO WORM!
    XConfiguration LoaderServicess.exeAdded by the GAOBOT.AO WORM!
    XConfiguration Loadersw32.exeAdded by the AGOBOT.BQ WORM!
    XConfiguration LoaderSystem.exeAdded by the GAOBOT.AO WORM!
    XConfiguration LoaderWinreg.exeAdded by the GAOBOT.AO WORM!
    XConfiguration Loadersysinfo.exeAdded by the GAOBOT.FQ WORM!
    XConfiguration Loadermicrosoft.exeAdded by the GAOBOT.JB WORM!
    XConfiguration Loaderconfgldr.exeAdded by the GAOBOT.GEN!POLY WORM!
    Xconfiguration loaderwinicfg32.exeAdded by the GAOBOT.RQ WORM!
    XConfiguration Loadersvhst.exeAdded by the GAOBOT.YC WORM!
    XConfiguration Loadermsgfix.exeAdded by the GAOBOT.AUS or SDBOT.J or SDBOT-QG WORMS!
    XConfiguration Loadermsnss.exeAdded by the GAOBOT.AUS WORM!
    XConfiguration LoaderIEXPL0RE.EXEAdded by the LOADCFG or SDBOT TROJANS!
    XConfiguration Loaderloadcfg32.exeAdded by the LOADCFG or SDBOT TROJANS!
    XConfiguration LoaderMSTasks.exeAdded by the LOADCFG or SDBOT TROJANS!
    XConfiguration Loadersystemry.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    XConfiguration LoaderccSort.exeAdded by the AGOBOT.SR WORM!
    XConfiguration Loadersmss32.exeAdded by the AGOBOT.MB WORM!
    XConfiguration Loaderwincffg.exeAdded by the AGOBOT.A3 WORM!
    XConfiguration Loaderseru32.exeAdded by the SDBOT-VR WORM!
    XConfiguration Loaderbotss.exeAdded by the SDBOT-XS WORM!
    XConfiguration Loaderldasp.exeAdded by the AGOBOT.BH WORM!
    XConfiguration Loadermsgcfgsrv.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    XConfiguration Loadersmsai.exeAdded by the SDBOT-YE WORM!
    XConfiguration Loadersvupdate.exeAdded by the RANDEX.DXP WORM!
    XConfiguration Loadercrcss.exeAdded by the AGOBOT.ADG WORM!
    XConfiguration Loaderlexplore.exeAdded by the RBOT-AGX WORM! Note - the executable is spelt with a lower case "L" rather than an lower or upper case "i" which is the case with Internet Explorer
    XConfiguration Loaderscvhost.exeAdded by the AGOBOT-AAE and SDBOT.AR WORMS!
    XConfiguration Loadersvchost.exeAdded by the PARADROP-A WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
    XConfiguration Loadersvchost2.exeAdded by the AGOBOT.JR WORM!
    XConfiguration Loaderdezi.exeAdded by the SDBOT-OB WORM!
    XConfiguration Loadermouse.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    XConfiguration Loadermsg.exeAdded by the SDBOT.BT WORM!
    XConfiguration LoaderWinHelper.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    XConfiguration Loaderextrac.exeAdded by the SDBOT-AFP WORM!
    XConfiguration LoaderDVD-Player.exeAdded by a variant of the SDBOT WORM!
    XConfiguration LoaderIEXPLORE.EXEAdded by the SDBOT-KW WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup unless you add it manually! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    XConfiguration Loadersvchost.exeAdded by the PARADROP-AI WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!
    XConfiguration Loaderwincore.exeAdded by the SDBOT.BHE WORM!
    XConfiguration Loaderconfigldr.exeAdded by the AGOBOT-PP TROJAN!
    XConfiguration Loaderahnhst.exeAdded by the AGOBOT.MX WORM!
    XConfiguration Loaderntdm.exeAdded by the AGOBOT.RV WORM!
    XConfiguration Loader ServiceWinsys32.exeAdded by the RBOT-YV WORM!
    XConfiguration Loader Servicedevl32.exeAdded by the SDBOT-XY WORM!
    XConfiguration Loader10ip7.exeAdded by the AGOBOT-ANZ WORM!
    XConfiguration Loadingsvchos1.exeAdded by the GAOBOT.DK WORM!
    XConfiguration Loadingconfigldr.exeAdded by the AGOBOT-EC WORM!
    XConfiguration Loading Servicewscel.exeAdded by the SDBOT-WJ WORM!
    XConfiguration Loadriexplore.exeeAdded by an unidentified WORM or TROJAN!
    XConfiguration ManagerCNFGLD32.EXEAdded by the SDBOT TROJAN!
    XConfiguration ManagerCnfgldr.exeAdded by the SDBOT TROJAN!
    XConfiguration Managercfg32.exeBookedSpace parasite. Note - the "cfg32.exe" file is located in the Winnt or Windows folder
    XConfiguration Serveciesewins.exeAdded by the SDBOT-COH WORM!
    XConfiguration Servicesuchost.exeAdded by the TREB TROJAN!
    XConfiguration Servicesmswords.exeAdded by the SDBOT-YM WORM!
    NConfiguration UtilityCONFIG.EXEControls linksys wireless connection. Available from the Desktop
    UConfiguration Utilitywlanutil.exeNetGear Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards)
    XConfiguration WizardCfgwiz32.exeAdded by a variant of the HACKTACK TROJAN! Not to be confused with the legitimate MS "ISDN Configuration Wizard" (Cfgwiz32.exe)
    XConfiguration32 Loader32winamp32.exeAdded by the SDBOT-BIC WORM!
    XConfLoadersysconf16.exeAdded by the SDBOT-FB TROJAN!
    NConmgrconmgr.exeStarts Winfax pro at startup
    UConMgr.execonmgr.exeConnection Manager as used by Earthlink and others. If you need this to ensure a proper connection but don't want to connect at startup try creating your own shortcut 
    Xconmswfconrnbne.exeAdded by the SDBOT-DEX WORM!
    UConnect KasambaKasamba.exe"Finding the expert help that you need is easy on Kasamba. With more than 30,000 registered experts in over 600 categories to choose from, chances are, we`ll have just the right professional in the exact area of expertise that you need"
    XConnect2Partyconnect2party.exeAdult content dialler
    UConnection KeeperConKeepM.exe"Connection Keeper is an invaluable time-saving tool for dial-up users. This free program simulates Internet browsing (at a random interval) to prevent your connection from appearing idle, thus preventing your ISP from dropping your connection due to inactivity"
    NConnection ManagerCManager.exeSBC Yahoo DSL service connection manager. You can connect from the network connections. Users having problems with this have been advised to uninstall the connection manager via Add/Remove Programs and it won't affect the service
    XConnectivity Tool[path to trojan]Added by the LITEBOT-E TROJAN!
    XConnectorSYS.EXEAdded by the dialer.Nunci premium dialer
    XConnectorsms.EXEAdded by the ExDial-B premium rate adult content dialer
    NCONNECTSchedulerCONNECTScheduler.exeScheduler for updating Sony's CONNECT music download service
    XConsconsol32.exeHijacker - redirects to a p0rn portal, where foistware like ISTBar gets stealth installed
    Xconscorrconscorr.exeVX2.Transponder parasite updater/installer related
    XConsole de Gerenciamento Microsoftcsrss.exeUnidentified malware! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a SystemLevel4 subfolder
    XConsole de Gerenciamento Microsoftcsrss.exeAdded by the BANCBAN-ET TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "Central de Seguran?a" subfolder
    UConsumer InputConsumerInput.exeConsumer Input Toolbar. Opt-in market research monitoring you browsing habits - see the FAQ
    UConsumer Input Rewarded with MyPoints, Consumer InputConsumerInputRewardedwithMyPoints, ConsumerInput.exeConsumer Input Toolbar. Opt-in market research monitoring you browsing habits - see the FAQ
    UConsumer Input Rewarded with MyPoints, Consumer Input UpdateConsumerInputRewardedwithMyPoints, ConsumerInputUa.exeConsumer Input Toolbar. Opt-in market research monitoring you browsing habits - see the FAQ
    ?Contactecontacte.exeSome kind of driver?
    XContent connector[random filename].exeAdded by the DIALER-Y TROJAN! Note - uses a random filename and random folders. Usually the folder containing the file is a Temp folder
    XContentDownloadrundll32.exe MSA64CHK.dll, DllMostrarMatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder
    XContentServicewinservn.exeHomepage hijacker
    XContinueInstallbpsinstall.exeBrowserAid/BrowserPal foistware
    XContraVirusContraVirusPro.exeContraVirus misleading security software - not recommended, see here
    XControlrundll32.exe ctrlpan.dll, Restore ControlPanelCoolWebSearch Msconfd parasite variant
    NControl CenterCenter.exeRelated to an Asus WLAN card
    XControl handler***********.exe [* = random char]CoolWebSearch parasite variant
    XControl handlerahjinst.exeCoolWebSearch parasite variant
    XControl handler[10 to 14 random char]THD.EXEAdded by the KREPPER-AI TROJAN!
    Ncontrol panelsmctrlw.exeSystem Tray icon for a Silicon Motion LynxEM based PCI Graphics Card
    XControl PanelSystem.exeAdded by the DANI TROJAN!
    Xcontrol panel software servicecprs.exeAdded by the RBOT-FPI WORM!
    XControladores[path to trojan]Added by the TELEFO-A TROJAN!
    NControlCenter2.0brctrcen.exeBrother scanner 'Control Center' application - can be started manually
    NControlCentreTrayXWCTray.exeSystem Tray access for the Xerox ControlCentre 2.0 software for their range of printers, copiers, faxes, etc
    XControlled Resource System Servicecrss.exeAdded by the AGOBOT.GH WORM!
    NControllerWFXCTL32.EXEFrom Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
    XControlPanelrundll32 internat.dll, LoadKeyboardProfileCoolWebSearch parasite variant
    XControlPanelhost32.exe internat.dll, LoadKeyboardProfileAdded by a vairant of the DELF.DW TROJAN!
    XControlPanelcmd32.exe internat.dll, LoadKeyboardProfileAdded by the DLOADER-HF TROJAN. Note - the "cmd32.exe" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    XControlPanelsystemctrl.exe internet.dll, LoadNetworkProfileBrowser hijacker, also detected as STARTPA-FX
    XControlPanelinternat.dll, LoadKeyboardProfileAdded by the BIZVES-A TROJAN!
    XControlPanelpopcorn.exe internat.dll, LoadKeyboardProfileAdded by the BIZVES-B TROJAN!
    XControlPanelpopcorn64.exeBrowser hijacker, redirecting to loadcash.biz
    XControlPanelpopcorn64.exe rundll.dll, LoadMouseProfileAdded by the DLOADER-OI TROJAN!
    XControlPanelpopcorn72.exe rundll.dll, LoadMouseProfileAdded by the DLOADER-RA TROJAN!
    XControlPanelsvcc.exeWorldSearch adware
    XControlPanelpopcorn320.exe rundll.dll, LoadMouseProfileAdded by a variant of the DLOADER-RA TROJAN!
    XControlPanelprivate.exe internat.dll, LoadMouseCarpetProfileReported by Norman Virus Control as W32/Downloader. Creates the files sdfff, fdsf and zxczxc. In the C:WINDOWSSYSTEM32 directory creates the files d.exe, s.exe and r.exe. Note - the "private.exe" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    XControlServiceMgrcsmsv.exeAdded by the AGENT-XC TROJAN!
    UCookie Cop 2CookieCop.exeCookie Cop 2 from PC Magazine - cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return
    UCookie PalCPBRWTCH.EXEKookaburra Software's Cookie Pal cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return
    UCookieJarCookiejar.exeCookie Jar cookie manager from Jason's Toolbox. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return. No longer being actively supported
    UCookiePatrolCookiePatrol.exeCookiePatrol - cookie interceptor stopping spyware cookies that used to be part of PestPatrol before CA's aquisition
    UCookieWallcookie.exeCookieWall from Analog X. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return
    UCool Deskcdesk.exeCool Desk is a virtual desktops manager. "Ever you wished to have several screens on your computer? Cool Desk creates up to 9 virtual desktops and offers you to have different windows on each of them". Not required but may be of use to you
    XCoolDownloadsrundll32.exe MSA64CHK.dll, DllMostrarMatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder
    UCoolMonCoolMon.exe"CoolMon monitors vital system stats and almost anything else you wish to display on the desktop"
    XCoolMP3rundll32.exe MSA64CHK.dll, DllMostrarMatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder
    UCoolSwitchtaskswitch.exeALT+TAB replacement Powertoy for Windows XP - enhances the graphics displayed when you want to switch between programs running full-screen
    NCoolwallpapercwm_tray.exeCool Wallpaper software allows you to manage high quality photos as desktop wallpaper and screen savers
    Xcoolwebprogramclrssn.exeCoolWebSearch Smartsearch parasite variant
    NCopernic Desktop SearchDesktopSearch.exeCopernic Desktop Search - "Easily search your entire hard drive in less than a second to pinpoint the right file, e-mail, music or pictures"
    UCopernic Desktop Search 2DesktopSearchService.exeCopernic Desktop Search - search agent
    UCopernicPerUserTaskMgrCopernicPerUserTaskMgr.exeAutomatic tasking feature of Copernic Pro multi-search engine tool
    YCopperheadrazerhid.exeRazer Copperhead mouse driver
    UCopy handlerCopy Handler.exeCopy Handler lets you copy between hard disks, floppies, local networks, CDs, and many other storage media. Copy Handler gives you the power to pause, resume, restart, and cancel during the copying and moving processes
    NCopyrightmwcpyrt.exeDisplays copyright information on IBM ThinkPads
    XCore Process Aplicationccapl.exeAdded by a variant of the RBOT WORM!
    XCore Process Aplication x16ccapl16.exeAdded by a variant of the SLAPER TROJAN!
    XCore Process Aplication x32ccapl32.exeDetected by Kaspersky as the SRAMLER.E TROJAN! See here
    UCoreCenterCoreCenter.exeMSI Core Center - motherboard utility for monitoring CPU speed, voltages, temperatures and fans speeds as well as overclocking
    UCoreCenterCORECE~1.EXEMSI Core Center - motherboard utility for monitoring CPU speed, voltages, temperatures and fans speeds as well as overclocking
    NCorel Colleagues & Contacts Reminderscffrem.exeCorel Colleagues & Contracts - all-in-one organizer for scheduling meetings, maintaining addresses, etc. Part of the now defunct Corel Print Office
    NCorel Desktop Application Directordadx.exeThe Desktop Application Director (DAD) gives you easy access to all Corel applications - x represents ther version number. Available via Start -> Programs
    NCorel Family & Friends remindersCFFREM.EXECorel Family & Friends - all-in-one calender, address book and list manager. Part of the now defunct Corel Print House Magic
    NCorel Photo DownloaderMediaDetect.exeRelated to Corel Photo Album
    NCorel RegistrationRemind32.exeIf you don't want to register Corel products and be reminded about it every 2 weeks disable it
    NCorel Registration ReminderRemind32.exeIf you don't want to register Corel products and be reminded about it every 2 weeks disable it
    NCorel ReminderNAVBROWSER.EXEIf you don't want to register Corel products and be reminded about it every 2 weeks disable it
    NCorel ReminderNAVBrowser.exeRegistration reminder for CorelDRAW 10
    NCorelCENTRAL 10I_26dadCC.exeCorelCENTRAL 10 - personal information manager (PIM). Supplied as part of Corel WordPerfect Office 2002. Available via Start -> Programs
    XCorelDraw ToolboxCorelDraw.exeAdded by the SDBOT-VZ WORM!
    NCorelMedia FoldersIndexer8MFindexer.exePart of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office
    NCorelMedia FoldersIndexer8MFINDE~1.EXEPart of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office
    XCoreSrvcoresrv.exeSome IRC trojans/worms use this - see here for more information
    ?CORESYScoresys.exe??
    XCorporate Microsoft Updateuptask.exeAdded by the RBOT-GVB WORM!
    NCorrectConnectCConnect.exeBroadband ISP diagnostic tool - as used by NTL and Cox Communications. Shortcut available
    Xcosinecosine.exeAdded by the RBOT-SW WORM!
    UCostAwareniIPCApp.exeNetInternals CostAware - download quota measuring tool
    XCounterstrike Service Agentczrzns.exeAdded by the MEDBOT.AR WORM!
    NCountry Selectpctptt.exeCountry selection for a PCtel HSP56 based modem. Often found in OEM (Dell,Compaq, HP, etc) systems for their modems included on the motherboard or as a separate card. Once you've set the modem up to the chosen country it's not required
    NCountrySelectionpctptt.exeCountry selection for a PCtel HSP56 based modem. Often found in OEM (Dell,Compaq, HP, etc) systems for their modems included on the motherboard or as a separate card. Once you've set the modem up to the chosen country it's not required
    ?Coupon Offers????
    Xcouponicacouponica.exeAdware - see here
    ?CPCopyProtectionNotifier.exeRelated to Emuzed Systems and Middleware. Comes included with Windows XP Media Edition
    UCP32NOTCP32BTN.EXEFor the programmable "one-touch" buttons on HP laptops (and others?). Safe to disable if you don't use these buttons
    UCP4HPOTOneTouch.EXEOne Touch keyboard driver. Required if you use the additional keys
    NCP888M1CP888M1.EXERelated to EZbutton quick launcher for the Media player app that comes with certain laptops
    ?CPA9P2PSERVERCPA9P2PS.exeFound on a Compaq Presario but what is it?
    Xcpanelwinlogin32.exeAdded by the RBOT-FOY WORM!
    UCPATR10CPATR10.EXEDritek/Compal ATR10 Easy Button driver. Used on certain laptops (e.g. Toshiba, Compaq) to translate special hotkeys such as Play/Pause and Constrast
    UCPBrWtchCPBrWtch.exeKookaburra Software's Cookie Pal cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return
    YCPD_EXECPD.EXEFirewall bundled with McAfee VirusScan 6.*
    Xcpldeamon.exeAdded by the TACTSLAY.C TROJAN!
    Xcplmsgaol.exeAdded by the TACTSLAY.C TROJAN!
    Xcpls_menu.exeAdded by the TACTSLAY.C TROJAN!
    Xcplbrowse.exeAdded by the TACTSLAY.C TROJAN!
    Xcplmsgaol.exeAdded by the TACTSLAY.C TROJAN!
    NCplBTQ00CplBTQ00.EXERelated to EZbutton quick launcher for the Media player app that comes with certain laptops
    NCPLDBL10CPLDBL10.exeRelated to EZbutton quick launcher for the Media player app that comes with certain laptops
    Xcpntmgcwincomp.exeAdded by the WINTRIM_A TROJAN!
    Xcpntmgcsimcss.exeAdded by the MAGICON.A TROJAN!
    Xcpntmgcnavpmc.exeAdded by the SIMCSS TROJAN!
    Xcpntmgcwinmgts.exeAdded by the WINTRIM-B TROJAN!
    ?CPortPatchcppatch.exeCPortPatch is a utility is required for Dell laptops that are using a docking station. Is it needed though?
    YCPQAcDcCPQAcDc.exeCompaq PowerCon power management software for laptops
    UCPQAlertCPQAlert.exeCompaq's Insight Manager Agent - a tool that allows for "fault, performance, and configuration management". Recommended for corporate users only. It's best removed if installed but not wanted, rather than disabled at startup. See here for more information
    NCPQBootPerfDBCPQBootPerfDB.EXESee the entry for Compaq Message Server
    YCPQCalibCPQCalib.exeCompaq PowerCon power management software for laptops
    NCPQDFWAGCpqDfwAg.exeFor Compaq PC's. Runs Compaq diagnostics on every boot
    UCPQEASYACCcpqeadm.exeFor Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
    UCPQEASYACCStartEAK.exeEasy Access Button Support for Compaq PCs. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keys
    UCPQEASYACCSTARTDRV.exeFor Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
    Ucpqeauicpqeaui.exeFor Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
    Ucpqekkcpqek.exeFor Compaq PC's. Easy Access button support for the keyboard
    UCPQInet Runtime ServiceCpqInet.exeFor Compaq PC's. Allows AOL and Compuserve to use the Easy Access buttons for the internet. Is not required if you don't use the ISP providers
    NCPQINKAGENTcpqinkag.exeThat is the Compaq Ink Agent for some inkjet printers, it lets users know when their ink cartridges are getting close to empty (by how many pages they have printed)
    Ucpqnscpqnpcss.exeRelated to Compaq.Net - not required if you don't use that
    NCpqsetCpqset.exeDefault settings software in Hewlett Packard notebook
    YCPQSTUTFIXstutfix.exeFor Compaq PC's. Fixes audio stutter problems for ESS Maestro soundcards. You can download it here. This is a Compaq originated file and has been verified as free from viruses by McAfree/Norton
    UCPQTEAMcpqteam.exeThis program is bundled with HP servers. When loaded a system tray icon will be available that launches the HP Network Configuration Tool
    XcprcprAdroar.com adware downloader
    Xcprocsvccproc.exeAdded by MSIL.AGENT.C TROJAN!
    XCPU Managercpumgr.exeAdded by the PANDEM.B WORM!
    XCPU Temp Controlwuitgurd.exeAdded by the RBOT-AHV WORM!
    XCPU Watcherrundll32.exe cpu.dll, loadAdded by the DLOADER-LO TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "cpu.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    XCPU Windows Statuscpustats.exeAdded by a variant of the RBOT WORM!
    UCPUcoolCpucool.exeProgram to keep the processor cool when idle in "overclocked" systems. Also available via Start -> Settings -> Control Panel
    NCPUMonCPUMon.exe"CPUMon continuously displays the updated system statistics in a floating window as well as in system tray area"
    XCpusaveCpusave.exeAdded by the GEMA TROJAN!
    XCpusave32Cpusave32.exeAdded by the GEMA TROJAN!
    XCPVHOST Settingscpvhost.exeAdded by a variant of the SDBOT TROJAN!
    Xcpythidep.exeAdded by the MIRJACK-A TROJAN!
    Xcqlygworld_cup_.batAdded by the WCUP.A WORM!
    ?CQSCP2P SERVER??"Compaq printer utility which is required in the startup menu in order to make the printer work correctly". Personally I doubt whether it is actually needed
    ?CQSCP2PS??"Compaq printer utility which is required in the startup menu in order to make the printer work correctly". Personally I doubt whether it is actually needed
    XCr**.exe [* = random char]Cr**.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
    XCr**.exe [* = random char]Cr**.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
    XCr**32.exe [* = random char]Cr**32.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
    Ucracked_windows1cracked_windows1.exeCracked Windows popup killer
    NCrazyTalk Serverundll32.exe CrazyTalk.dll, DIIServeMediaFileCrazyTalk from Reallusion - "the worlds only facial animation tool that gives you the power to create talking animated images from a single photograph, complete with emotions." Can apparently be installed without your knowledge as well as being a legitimate download in it's own right from sites such as TUCOWS
    UCRBroadCastingCRBroadCasting.exeCardReader2 from On Track Inovations Ltd. USB Card Reader
    XCRC Value Verifiercrsss32.exeAdded by a variant of the RBOT WORM!
    XCRC Value VerifierCrsss64.exeAdded by the RBOT-NY WORM!
    XCRC Value Verifiersvchost32.exeAdded by the RBOT-OA WORM!
    XCRC Value Verifiercrsss.exeAdded by the SPYBOT.UK WORM!
    XCrc32stats DependenciesCrc32stats.exeAdded by the MYTOB.GT WORM!
    XCRCSScrcss.exeAdded by the IRCBOT-TH WORM!
    UCreata MailJMSrvr.exeCreata_Mail. Smileys, stationary and more for you email. Required if you want to access the program from Outlook or Outlook Express
    XCreate A MonstercreateAMonster.exeKudd.com CreateAMonster. Reportedly stealth installed and Look2Me adware related
    NCreateCDCreatecd.exeAdaptec Easy CD Creator system tray application (pre version 5). Available via Start -> Programs
    NCreateCD50Createcd50.exeAdaptec Easy CD Creator version 5 system tray application. Available via Start -> Programs
    XCreates stractures for system managementstacture.exeAdded by the SDBOT-DHS WORM!
    NCreative AGP Wizardagpwiz.exePart of Creative's BlasterControl
    XCreative Audio Driverscreative.exeAdded by the RBOT-FKR WORM!
    NCreative DetectorCTDetect.exeAuto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player, selecting Tools, then uncheck the Auto Start box. It should not start up automatically again
    NCreative LauncherCTLauncher.exeFor Creative Soundblaster Live! series soundcards. Adds a quick-launch bar to the top of the display and a System Tray icon. Available via Start -> Programs
    UCreative Live! Cam ManagerCTLCMgr.exeCreative Live! Cam Manager
    NCreative MediaSource GoCTCMSGo.exe"Creative MediaSource playbacks music in DVD-Audio, MP3, WMA, WAV and other media formats"
    NCreative MediaSource GoCTCMSGoU.exeCreative MediaSource playbacks music in DVD-Audio, MP3, WMA, WAV and other media formats"
    NCreative PCI Audio Configuration Utilitystarter.exeSystem Tray icon to configure a Creative Soundblaster PCI soundcard. Not required and re-instates itself when un-checked. Try one of the solutions on this special page. Similar to EnsoniqMixer
    NCreative Service for CDROM AccessCtsvccda.exeResident program for Creative's PlayCenter included with Soundblaster Audigy sound cards - speeds up detection of some media CDs if the system doesn't natively support them. Available via Start -> Programs
    NCreative Software UpdateAutoUpdate.exeAuto-updater for Creative Labs software
    NCreative WebCam TrayCamtray.exeCreative WebCam tray control - can be started manually
    XCreative.exeCreative.exeAdded by the PROLIN WORM!
    NCreativeDiscNotifierCTNOTIFY.EXEFor Creative Soundblaster Live! series soundcards. Detects when you insert a CD-ROM, DVD-ROM, etc. Available via Start -> Settings -> Control Panel
    UCreativeMixerCTMIX32.EXECreative soundcard System Tray access to, for example, volume slider controls as normally provided by the "speaker" icon. Not required unless you adjust any settings otherwise available via the standard icon
    ?CreativeTaskSchedulerCTSched.exeCreative Task Scheduler. What does it do and is it required?
    XCritical Error Safe32GetWaylayer32.exeAdded by the RBOT.IAL WORM!
    XCritical Update Checkbattlenet.exeAdded by the DELF-LB TROJAN!
    NCriticalUpdateWucrtupd.exeMS Windows Critical Update Notification. If you want to keep Windows up-to-date, check the Windows Update site
    XCriticalUpdatewucrtupd.exeAdded by the NOALA.B WORM! Note - this file is located in the Windows or Winnt folder, and must not be confused with the legitimate Windows process of the same name as described here
    Xcrmssrlt[random filename]Added by a variant of the SLAPER TROJAN!
    XCrnsavascrnsave.pifAdded by the SDBOT-ZV WORM!
    XcronosMARCO!.SCRAdded by the OPASERV.G WORM!
    XCrossMenuCrossMenuToshiba CrossMenu Utility - allows the user to create their own menus
    XCRP386 Networkingcrp386.exeAdded by the IRCBOT.N TROJAN!
    Xcrscrs.exeAdded by the AGOBOT-TJ WORM!
    XCRSSXP SysInfocrssxp.exeAdded by a variant of the SDBOT TROJAN!
    XCrustydmcpl.exeAdded by the RUSTY WORM!
    Xcryptdlgcryptdlg.exeAdded by an unidentified TROJAN!
    Ucryptoexpertcexpert.exeCryptoExpert from SecureAction Research. Advanced on the fly encryption system
    XCryptographic Service******.exe [* = random char]Added by the KORGO.W or KORGO.X or KORGO.AB WORMS!
    ?Crystal 3D Audio ControlCWD3DSND.EXECrystal 3D Audio sound driver. Is it required?
    XCS Updatecopy /Y [path] ActivationManager.dll.upd [path] ActivationManager.dllAdded by an unidentified malware
    NcsaRemspqmdmui.exeCompaq modem country selection
    YCSAV_CheckVirusesvchk.exeCommand Antivirus related
    Ucsccsc.exeCommand line compiler for Microsoft C# it gets installed with the .NET SDK
    XCSCRS Valuecscrs.exeAdded by the RBOT-AAA WORM!
    XCSCRS Value CheckMsPMSPSd.exeAdded by a variant of the SDBOT WORM!
    UCSINJECT.EXECSINJECT.EXEPart of Quarterdeck/Norton CleanSweep. "Csinject must be loaded in order for Smart Sweep to automatically monitor installations and properly track registry changes"
    Xcsm Win Updatescsm.exeAdded by the ZOTOB.B WORM!
    XCSNetManagerXpisass.exeAdded by the HIDER-O TROJAN!
    Xcsoftoksoftok.exeAdded by the QQPASS.G TROJAN!
    Xcsoscsos.exeAdded by the SDBOT-DFE WORM!
    Xcsrscsrs.exeAdded by the GAOBOT.GEN!POLY WORM!
    Xcsrsccsrsc.exeAdded by an unidentified VIRUS, WORM or TROJAN!
    XCSRSSCSRSS.EXESearch page hijacker, redirecting to http://www.search-aide.com/. Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
    XCsrsscsrss.exeAdded by the CHOD WORM! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup and the executeable resides in a random folder name
    Xcsrsscsrss.exeAdded by the KEYLOG-AQ KEYLOGGER! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
    Xcsrsscsrss.exeAdded by the CHODE-J WORM! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a random subfolder
    Xcsrssmsmsgs.exeAdded by the CHODE-J WORM!
    Xcsrssnwiz.exeAdded by the CHODE-J WORM!
    Ucsrsscsrss.exeBeyondKeylog surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Program Files/Supremtec folder
    XCsrssCSRSS.EXEAdded by the PUNYA-B WORM! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
    Xcsrssssms.exeAdded by an unidentified malware
    XCSRSS Loadercsrsss.exeAdded by the AGOBOT.TX WORM!
    Xcsrss.execsrss.exeAdded by the DALBUG WORM! Note - this is not the legitimate csrss.exe process which is always located in the WinntSystem32 or WindowsSystem32 folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
    XcsrssLevel4csrss.exeUnidentified malware. Note - this file is placed in a C:WindowsSystemLevel4 folder, and should NOT be confused with the legitimate csrss.exe process which is always located in the WinntSystem32 or WindowsSystem32 folder and should NOT figure in Msconfig/Startup!
    XCSRSSUCSRSSU.exeCoolWebSearch parasite variant - hijacking to Slawsearch.com. Also detected as the CWS-E TROJAN!
    XCSRSSWCSRSSW.EXEAdded by the CWS-F TROJAN!
    XCSRSWIN[trojan filename]Added by the WINSHELL.50 TROJAN!
    XCSRSX[trojan filename]Added by the WINSHELL.50.B TROJAN!
    Xcsrvsscsrvss.exeAdded by a variant of the SDBOT TROJAN!
    UCSS ServerCSSServer.exeComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself
    Ucssauthcssauth.exeRelated to IBM ThinkVantage Client Security Solution
    ?cssauthecssauthe.exePart of the Client Security Solution on an IBM ThinkVantage (now Lenovo) PC - "a suite of ThinkVantage Technology tools designed to help protect access to your computer operating system and your sensitive data. The Client Security Solution integrates the hardware protection of its embedded chip with the protection afforded by its secure software." What does this do and is it required?"
    YCSScheduleCheckSCHWIZEX.EXEPart of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot
    Xcssrscssrs.exeAdded by the BANCBAN-DW TROJAN!
    XcsssCsss.exeAdded by the BALICK TROJAN!
    UCSS_CentralCSS_1631.EXECSS Communication Agent (95 Host) from Command Software Systems (now Authentium). "CSS Central? provides administrators with a powerfully proactive tool to effectively manage and maintain the anti-virus strategy from a centralized console"
    XCSV10P1CSP001.exeClearSearch adware
    XCSV10P70CSv10P070.exeClearSearch adware
    XCSV7P26CSV7P26.exeClearSearch adware
    XCSV7P70CSV7P070.exeClearSearch adware
    XCSV7P91CSV7P91.exeClearSearch adware
    Ucsvdeacsvdea.exeSpyArsenalLog surveillance software. Uninstall this software unless you put it there yourself
    Xcsvhost.execsvhost.exeAdded by the CIMUZ-BD TROJAN!
    Yctct.exect.exe is a file is for the HP Learning Adventure software and if you use this software it is required to run it
    XCT Control SettingsCTSVCCD.EXEAdded by the RBOT-YS WORM!
    UCTAPR2CTAPR2.exeConsole Launcher for the Creative Sound Blaster X-Fi series
    NCTAVTrayCTAvTray.exeFor Creative Soundblaster Live! series soundcards. Plays the EAX animation on start-up and adds a System Tray icon for it. Available via AudioHQ
    UCTCMonitorCTCMonitor.exeClick-to-Convert - document-to-HTML or doc-to-PDF converter. Only required if you are going to use the File -> Print method of using Click-to-Convert. If converting directly from MS Office, it is not required
    XCTDriverundll32.exe drvmod.dllAdded by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "drvmod.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    NCTDVDDetCTDVDDet.exeAuto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player, selecting Tools, then uncheck the Auto Start box. It should not start up automatically again
    NCTDVDDetCTDetect.exeAuto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player, selecting Tools, then uncheck the Auto Start box. It should not start up automatically again
    Xctf.exectf.exeAdded by a variant of the BIFROSE TROJAN!
    Xctflog managerctflog.exeAdded by the DONBOMB.A TROJAN!
    XCTFM0N.exeCTFM0N.exeAdded by the STARTPAGE.P TROJAN!
    Uctfmonctfmon.exeCTFMon is involved with the language/alternative input services in Office XP. Ctfmon.exe will continue to put itself back into MSConfig when you run the Office XP apps as long as the Text Services and Speech applets in the Control Panel are enabled. Not required if you don't need these features. For more info on ctfmon see here. Ctfmon can be disabled from Control Panel, Text & Speech Services. Note - the file will always be located in the System32 folder, if it is located elsewhere it will likely be a worm or trojan! Can cause problems with some other programs if left enabled - see here for such an example
    Xctfmontaskmgr32*.exe [* = number]Added by the SOWSAT.B WORM!
    Xctfmoncftmon.exeAdded by the DELIVE-A TROJAN! Note - this file is found in C:Windows or C:Winnt and is not the valid MS Office file of the same name (see here)
    XctfmonmIRC.dllAdded by the DELBOT-E TROJAN!
    XctfmonWinConst.exeAdded by the ASSASIN-G TROJAN!
    UCTFMonctfmon.exeFamily Keylogger is a program that lets you record to a special file and then view all the keystrokes typed by everyone using your computer. Keystroke logger/monitoring program - remove unless you installed it yourself! Found in the SystemCTF (9x/Me) or System32CTF (NT/2K/XP) folder
    Xctfmonmsnmsgr.exeAdded by the JV TROJAN!
    XCtfmon.exectfmon32.exeCoolWebSearch Ctfmon32 parasite variant
    Xctfmon.exectfmon.exeAdded by the RAIDYS TROJAN! Note - this should not be confused with the valid Office XP file, see here
    Xctfmon.exemsupdate32.exeSpy Sheriff/SpywareNO malware, also detected as the SPYHOAX-A TROJAN, pretends to be a spyware remover! - file names spotted sofar include VXH8JKDQ2.EXE, NS6281400.so, CVXH8JKDQ2.EXE, down3.exe, sefe.exe, winstall.exe, and tool2.exe
    Uctfmon.exectfmon.exeCTFMon is involved with the language/alternative input services in Office XP. Ctfmon.exe will continue to put itself back into MSConfig when you run the Office XP apps as long as the Text Services and Speech applets in the Control Panel are enabled. Not required if you don't need these features. For more info on ctfmon see here. Ctfmon can be disabled from Control Panel, Text & Speech Services. Note - the file will always be located in the System32 folder, if it is located elsewhere it will likely be a worm or trojan! Can cause problems with some other programs if left enabled - see here for such an example
    Xctfmon.exectfmon.exe eminem.exeAdded by the BHARAT.A WORM!
    XCTFMON32CTFMON32.EXECoolWebSearch Ctfmon32 parasite variant - also detected as the CWS-E TROJAN!
    Xctfmon32[random filename].exeAdded by the RBOT-GSN WORM!
    Xctfmonactfmona.exeAntiVirusPro misleading security software - not recommended, see here
    XCTFMONSSCTFMONSS.EXEAdded by the CWS-F TROJAN!
    XctfnomrundIl32.exeAdded by the LEGMIR-AW TROJAN!
    Xctfnom.exeSVOHOST.exeAdded by the DIGIDOR-A TROJAN!
    Xctfnom.exeOSRSS.exeAdded by the DLOADER-UQ TROJAN!
    UCTHELPERCTHELPER.EXECTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative's sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a "leave alone" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need it
    XCTHelpercthelper.exeAdded by the RBOT-XB WORM! Note - do not confuse with the Creative application of the same name described here
    XCTime[path to trojan]Added by the HTTPDOS TROJAN!
    XCTin10CTin10.exeAdded by the BANCOS.E TROJAN!
    XCtModuleCtModule.exeAdded by the CLICKER-EG TROJAN!
    UCTNMRUNctnmrun.exeDetects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use to copy MP3 files to and from it. This is required if you want PlayCentre 2 to take control of the NOMAD once connected
    ?CTPDPSRVCTPDPSRV.EXEPrinter driver (in the WINDOWSSystem32spoolDRIVERSW32X86 folder). Is it required?
    NCTPerformanceUtilityCTPowUti.exeRelated to Creative PowerSysTrayApp. This program is a non-essential process, but should not be terminated unless suspected to be causing problems
    Xctpmonctpmon.exeSystem Registry Cleaner - stealth installed foistware from sysregistry.com
    NCTRegRunCTRegRun.exeFor Creative Soundblaster Live! series soundcards. Reminds you to register your card with Creative
    UCtrlVolCtrlVol.exeVolume control key on Acer, Fujitsu and other laptops
    ?CTSchedCTSched.exeCreative Task Scheduler. What does it do and is it required?
    NCTStartupCTEaxSpl.exeSplash screen with sound on every boot up. Installed with a Sound Blaster Audigy soundcard
    UCTSVolFECTSVolFE.exeCreative Labs Mixer applet for the Sound Blaster Audigy
    UCTSVolFE.exeCTSVolFE.exeCreative Labs Mixer applet for the Sound Blaster Audigy
    NCTSyncU.exeCTSyncU.exeCreative Sync Manager - synchronizes music tracks on your computer with your player
    UCTsysVolCTSYSVOL.exeCreative sound card volume controls
    ?cttdpsrvcttdpsrv.exe??
    XCTUpdatectupdclt.exeAdded by the RBOT-ABG WORM!
    NCTxfiHlpCTXFIHLP.EXEAdded by the installation of a Creative Labs X-Fi sound card. This particular process provides the help functionality for your card
    NCTXFIREGCTxfiReg.exeCreative Labs sound card driver related. It appears that it isn't required and maybe registration related
    XCtykd[path to file]SMALL.SN spyware
    NCTZDetec.exeCTZDetec.exeAuto-detect feature of Creative Media Lite which assists you in managing your music, ripping CDs and transferring other stored music to your Zen Stone MP3 player
    XCU1VCClient.exeAssociated with the Surf Sidekick adware and should be removed
    XCU2VCMain.exeAssociated with the Surf Sidekick adware and should be removed
    YcuagentExeCuagent.exeCommand Antivirus related
    XCueX44Dago.exeAdded by the PUNYA-B WORM!
    XCueX44_stil_hereWINLOGON.EXEAdded by the PUNYA-A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
    Xcuocuo.exeAdded by the BUGBEAR.A WORM!
    XCurrent Security Configcsecure.exeAdded by the RBOT-AMO WORM!
    NcursorScreendragon_
    VS_Taskbar.exe
    ScreenDragon video player
    NCursorXPCursorXP.exeCursorXP from Stardock - tool for creating mouse cursors
    UCustomizer2000logon.exeAutomatic logon feature of Customizer 2000 - "a special utility which is designed to optimize Win9x/ME performance. The program lets you explore the many hidden settings in Windows, and make changes"
    NCuteMXCuteMX.EXEFile sharing utility
    XCvfjxANACON.EXEAdded by the NACO.A WORM!
    Xcvmonitor.execvmonitor.exeAdded by the SDBOT.BV WORM!
    Xcvmsyslpdsdservss.exeAdded by the MAILBOT-BY TROJAN!
    YCVPNDcvpnd.exeSub-system used by Cisco VPN client for making a connection to a remote IPSec server
    UCWcw4.exeChat Watch "is a monitoring and logging software for online chat and instant messaging programs"
    UCWatchcw.exeChatWatch - chat monitoring tool
    Ncwbckvercwbckver.exePart of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Checks the software version on your PC to that of the iSeries it is connected to. Not required - and can be turned off in the Client Access properties. It's a waste of resources
    Ncwbinhlpcwbinhlp.exeClient Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. It only updates the help files on your PC to match the level of the attached iSeries
    Ncwbsvstrcwbsvstr.exePart of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Useful if you are going to access the iSeries through Windows Explorer to move files back and forth between Windows folders and iSeries folders. This is a tool that is only used by Client Access administrators (usually) so it is not required - a waste of resources
    ?cwbwlwizcwbwlwiz.exeWelcome wizard launcher - Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. What does it do and is it required?
    ?Cwcdschk.exeCwcdschk.exeIBM Thinkpad related?
    Ucwcptraycwcptray.exeRelated to ContentWatch Parental Control internet filter
    Xcwingllibatllsimm.exeAdded by a variant of the SDBOT WORM!
    Ucwupdatecwupdate.exeContentProtect from ContentWatch - internet filter
    NCXMonHpi_Monitor.exeAutodetects when a HP camera is attached to the computer and launches the "HP Photoimaging Software". Available via Start -> Programs
    NCybercyberchk.exePart of Belkins "Multimedia Cleaning Kit" and is automatically installed when you run their optical disk drive cleaning utility - to remind you to clean your drive after "x" amount of time has passed
    UCyber Trioshowmode.exeFrom G-Tek Technologies. Allows you to set the PC in one of three modes, Standard, Enhanced and Kiddo. Standard is full function, Enhanced prevents accidental damage and Kiddo is a play environment for kids. Pre-installed on some Packard Bell PCs
    UCyber-Defender 2003uwcdsvr.exeCyber Defender 2003
    Xcyberfree.exe****.dat [* = random char]Unidentified adware
    UCyberhawkCHTray.exeCyberhawk from Novatix. Protects against viruses, spyware, identity theft
    UCyberLat Ram CleanerCLRamCleaner.exeCyberLat RAM Cleaner - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
    UCyberLat Ram CleanerCyberLat Ram Cleaner 1.1.exeCyberLat RAM Cleaner - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
    NCyberMedia AgentCMAGENT.EXEPart of CyberMedia's Oil Change program. Not normally required. Note - if you have TextBridge, CyberMedia Agent may attach itself to TextBridge and cause TextBridge to crash everything if this is disabled
    UCyberPatrolNewcphq.exe"CyberPatrol is one of the most powerful and popular client-based, browser independent, Internet safety software solutions for Windows-based standalone PCs available today"
    XCyberWolfCyberWolf.exeAdded by the KICKIN.A (or CYDOG.C) WORM!
    XCyDoorCD_Load.exeAdware. Check here for information about Cy-Door and here for a program that can remove it
    XCydoorUpdateCD_Load.exeAdware. Check here for information about Cy-Door and here for a program that can remove it
    ?CYNHKeyCYNHKey.exe??
    NCyphTrayCyphTray.exeCypherus - encryption software
    UCypressLinkMonCypressLinkMon.exeRelated to CypressViewer from Siemens that "allows ACUSON Cypress cardiovascular system PLUS users to store, view, and analyze Cypress system PLUS studies on a standard Windows PC"
    XD SYSTEMdd.exeAdded by the MYTOB-FN WORM!
    YD-Link Air USB UtilityAirCFG.exeD-Link wireless PCI adapter related
    YD-Link Air UtilityAirCFG.exeD-Link wireless PCI adapter related
    ND-Link AirPlus DWL-650+ UtilityWLANMON.exeD-Link Air Plus Wireless PC modem connection monitor
    YD-Link AirPlus GAirGCFG.exeD-Link Airplus Wireless Router driver
    YD-Link AirPlus G Wireless UtilityAirPlus.exeD-Link AirPlus G wireless configuration and monitoring utility
    UD-Link AirPlus XtremeGAirPlusCFG.exeD-Link AirPlus XtremeG wireless configuration utility
    ND066UUtilityD066UUTY.EXETWAIN driver for the CanoScan D660U flatbed scanner. Start scanning via your scanner management software
    XD3**.exe [* = random char]D3**.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
    XD3**32.exe [* = random char]D3**32.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
    Xd3dupdate.exebbeagle.exeAdded by the BEAGLE.A WORM!
    UD4D4.exeDimension 4 - network time synchronization freeware - starts-up, adjusts the system clock, then shuts down
    Xdabrunrundll32.exe dabapi.dll, Rundll32SinaUpdateCenter adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "dabapi.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    NDACONFIGEXEdaconfig.exe3Com NIC Diagnostics. Available via Start -> Programs
    YDadAppdadapp.exe"DadApp is the SW utility that controls the programmable buttons on Dell Laptops. Not required, but should be left in because it can create a hassle and doesn't always restore functionality to those buttons once unchecked and rechecked" - direct from Dell
    NDaemonDAEMON32.EXEPre-loads game profiles for MS Sidewinder game controllers prior to release 2.0 of the software. Recommend upgrade. Available via Start -> Programs
    UDaemonDaemon.exeDaemon Tools - used to map an image-file (.iso, .bin etc) to a virtual CD/DVD-drive
    XDaemondaemon.exe c daemon2.exeAdded by the SELOTIMA.A WORM!
    UDAEMON Toolsdaemon.exeDaemon Tools - used to map an image-file (.iso, .bin etc) to a virtual CD/DVD-drive
    UDAEMON Tools Pro AgentDTProAgent.exe"DAEMON Tools Pro converts your computer games CD/DVD discs into "virtual discs" or so called ?disc image? files, which run directly on your hard drive"
    UDAEMON Tools-1033Daemon.exeDaemon Tools - used to map an image-file (.iso, .bin etc) to a virtual CD/DVD-drive
    Xdagofault.exeAdded by the PUNYA-A WORM!
    NDaily Plannerdayplan.exeDaily Planner - discontinued, and now part of KMCS Deluxe System Suite. Tool to plan your days, and check activities off as you complete them
    XDaily Weather Forecastweather.exeAdded by the DLOADER-IP TROJAN!
    XDamedWare Servicesdwdrce.exeAdded by the RBOT-AOJ WORM!
    XDanBtR270414DanBtR270414.exeAdded by the VB-NIB WORM!
    UDancerDncLE.exePart of Microsoft Plus! Digital Media Edition - see here
    XDanton*[random filename]Added by the DANTON TROJAN! where * = random number
    NDapDAP.exeDownload Accelerator Plus from Speedbit. Download manager for resuming downloads, amongst other features. Available via Start -> Programs. Note that the free version is adware based
    Xdarkimgst.scrAdded by the BANCOS.U TROJAN!
    Xdarkimgrt.scrAdded by the BANCBAN-FH TROJAN!
    Xdarkcsrs.scrAdded by the BANCBAN-GT or BANCBAN-GU TROJANS!
    XDarkDevil.Grasiele.BRGrasiele.VBSAdded by the LEMBRA WORM!
    XDarKNesS LsasSLsasS23.exeAdded by an unidentified WORM or TROJAN!
    ?DashIEN/ACould be related to "Dash Power Shopping" tool bar in IE?
    Xdaskaskfsak6dsfids6.exeAdded by the ONLINEG-J TROJAN!
    Xdaskgfkkcx15dasdsaads15.exeAdded by the ONLINEG-Q TROJAN!
    Xdasxdadsfsdqd.exeAdded by the GAOBOT.BIQ WORM!
    XDataSystem.dat.vbsAdded by the BISCUIT.A WORM!
    Xdatamsngs.exeAdded by the RBOT-ADQ WORM!
    NData LifeGuardBACKWE~1.EXEData LifeGuard diagnostic tools for Western Digital's series of hard drives
    NData LifeGuard LifeLine Lite installerDLGLI.EXEBackweb installer - see here
    XData Restore Serviceprq8.exeAdded by the KELVIR.AI WORM!
    XData789Regedit.exe ....data789.tmpHomepage hijacker
    XDATABASE MySql[path] repcale.exe [path] beird.exeAdded by a variant of the RANDON.AN WORM!
    NDataCachingFlashKsk.exeSmartMedia Card management from the installation of a SanDisk reader for a camera's SmartMedia card and also adds the "Unplug and Eject Hardware" System Tray icon
    UDataKeeperDataKeeper.exePowerQuest DataKeeper (now owned by Symantec) backup software
    UDataLayerDataLayer.exeNokia PC Suite 5 - "A collection of powerful tools that you can use to manage your phone features and data." Synchronize the phone with, for example Outlook. You can also use it to browse your phone, edit the phone list and so on
    NDataViz Inc MessengerDvzIncMsgr.exeInstalled with DataViz "Documents to Go" software
    NDataViz MessengerDvzMsgr.exeDataViz Documents to Go - "allows you to use your Word, Excel and PowerPoint files on your handheld anywhere, anytime. In addition, it now synchronizes e-mail with attachments, PDF files, pictures and Excel-like charts"
    XDatcheckdatcheck.exeAdded by the KEYPANIC TROJAN!
    XDate Managerdatemanager.exeDate Manager - calender program. Spyware/adware based provided by The Gator Corporation. Please note that Claria Corporation no longer support GAIN-Supported software - see here
    ?DatecheckerN/ACould be related to this?
    XDateMakerIntlDateMakerIntl.exePremium rate adult content dialler
    XDAupdateDAupdate.exeNavEnhance adware
    ?DAW9532.exeDAW9532.EXELoaded during installation of some 3Com network cards. Enables their DynamicAccess desktop management software. Is it required?
    UDayTodayDAYTODAY.EXEDayToday from RoboMagic Software Corp. Displays the date on the taskbar
    UDAZEL Delivery AgentDcDaemon.exeControl and send documents, etc, to any destination. The Dazel Corporation has now been taken over by HP
    Xdbar_starterstarter.exeDeskbar adware - adds a search bar to your Windows taskbar which performs searches on www.w-w-w-dot-com.com
    XDbgHlp32DbgHlp32.exeAdded by the WINKO.AO WORM!
    UDBISQL9dbisqlg.exeRelated to SQL Anywhere from Sybase. A comprehensive package providing data management and data exchange technologies
    Ndbservdbserv.exeDatabase Server for Norton Ghost on Win2k Pro. Ghost works fine when it is disabled
    Xdcdc.exeAdded by the COIDUNG-A WORM!
    Xdc2k5SVIQ.EXEAdded by the COIDUNG-A WORM!
    UDC300 Monitorcmonitor.exeMonitor for a Acer DC300 digital camera
    XDC6CWDC6CW.EXEDriveCleaner misleading security program - not recommended, see here
    XDC6_Checkuwasdc.exeWinAntiSpyware 2006 spyware remover - not recommended, see here
    XDC6_checkdc6_startupmon.exeWinAntiVirus 2006 misleading virus software - not recommended, see here
    Xdc6_checkdcmon.exeSystemDoctor misleading security software - not recommended, see here
    XDCE Managerdcemgr.exeAdded by the TUMAG TROJAN!
    UDCfssvcdcfssvc.exeAssociated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup, your camera will not cause your computer to open a pop-up window when you connect it. Leave enabled if you can't load pictures from your camera/dock - Kodak's dock is an example
    Udcfssvedcfssvc.exeAssociated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup, your camera will not cause your computer to open a pop-up window when you connect it. Leave enabled if you can't load pictures from your camera/dock - Kodak's dock is an example
    XDcom System PatchMicrosoft.exeAdded by the RANDEX.MS WORM!
    Ndcsmdcsm.exeDriveCleaner is a security assesment tool which gives exaggerated reports of security and privacy risks on a computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported risks
    NDDCActiveMenuDDCActiveMenu.exeDigital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
    NDDCMDDCMan.exeDigital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
    NDDCManDDCMan.exeDigital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
    Xddeprocddeproc.exeWebcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Now no longer available and supported and when available was classed as spyware - see here
    UddhelperW815DM.EXEEnuff Parental Control Software by Akrontech
    XDDiallerDDialler.exeAdult content dialler
    Xddivmwa[random filename]Added by a variant of the SLAPER TROJAN!
    Uddoctorv2sprtcmd.exe /P ddoctorv2Comcast Desktop Doctor (provided by SupportSoft, Inc) is a free self-help tool for Comcast broadband users. Identifies and automatically fixes typical problems that may occur with your high-speed internet service
    XDDriverwindrv.exeAdded by the DELF.WG TROJAN!
    XDDriversvchost.exeAdded by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
    ?DDTN/A??
    UDDWMonddwmon.exeDirect Disc Writer Event Monitor from TOSHIBA
    Xde32gende32gen.exeAdded by a variant of the CRYPTER.C TROJAN!
    NDeadAIMrundll32.exe DeadAIM.ocm, ExportedCheckODLsDeadAIM - feature enhancing product for AOL's Instant Messenger program
    XDeadKittyDeadKitty.exeAdded by the DEADCAT-A WORM!
    XDealHelperBrwsrdhbrwsr.exeDealHelper adware
    XDealHelperDowndownload.exeDealHelper adware
    XDealHelperUpdateDHUpdt.exeDealHelper adware
    XDeath.exeDeath.exeAdded by the DELF-ERW TROJAN!
    XDebugDebugW32.exeAdded by the GUBED TROJAN!
    XDebuggerdbg32.exeAdded by the MYTOB-FW WORM!
    XDebuggerexplorer32dbg.exeAdded by the CWS-M TROJAN!
    XDebuggeriexplore_dbg.exeAdded by the CWS-M TROJAN!
    Xdebuggerhelp.pifAdded by the DELF-DRA WORM!
    XDebugMonitordebugmonitor.exeAdded by the MYDOOM.BG WORM!
    UDeeEnEsDeeEnEs.exeDeeEnEs - automatically updates a dynamic IP address when it changes
    Xdeejayforboo.exeAdded by the FORBOT-AY WORM!
    XDeewooncntnkwd.exeIdentified as a variant of the AdWare.Win32.ZenoSearch.am malware
    XDefaultexplore.vbsAdded by the ALLEM WORM!
    XDefaultmtask.vbeAdded by the ALLEM WORM!
    Xdefaultshell32.exeAdded by the BINGHE TROJAN!
    XDefault_default.pifAdded by the RUBBLE-C WORM!
    XDefault System Researchvhchost.exeAdded by the TARNO.I TROJAN!
    XDefault web browserIexpIore.exeAdded by the OBLIVION.B TROJAN! Note - do not confuse "IexpIore.exe" with "iexplore.exe" (Internet Explorer), the first has a captial "i" in place of lower case "L"
    XDefault_Page_URLhttp://find.naupoint.comNaupoint browser hijacker
    XDefault_Search_URLhttp://find.naupoint.comNaupoint browser hijacker
    Xdefenderdefender25.exeDollarRevenue adware
    Xdefenderdfndref_7.exeDollarRevenue adware
    ?deferguidefergui.exeRelated to IBM Standard Software Installer. What does it do and is it required?
    Xdefragm_checkdefragment.exeCoolWebSearch parasite variant
    Xdefragsyssvchost.exeAdded by the BIFROSE-TH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
    Udefwatchdefwatch.exeDetects out-of-date virus definitions for Norton Anti-Virus Corporate Edition and runs the Defwatch Wizard. Only required if you don't update the virus definitions manually on a regular basis
    UDeko550Deko550.exeAssociated with the Deko550 entry-level SD real-time graphics system from Avid Technology
    UDelaydelayrun.exeOn HP PCs this program is used to help prevent conflicts or timing issues on fast computers
    UDelayrundelayrun.exeOn HP PCs this program is used to help prevent conflicts or timing issues on fast computers
    ?delcabdeltreew.exe C:cabs??
    XDelete Meworm.exeAdded by the DOOMHUNTER WORM!
    UDeleteHistoryFreedhf.exeDelete History Free - "Privacy protection software for deleting Internet surfing and other computer activity tracks from your PC"
    NDell AIO Printer A***dlbabmgr.exeDell AIO Printer A*** related (*** = model). Not Required at Startup
    NDell AIO Printer A***dlbfbmgr.exeDell AIO Printer A*** related (*** = model). Not Required at Startup
    NDell AIO Printer A***dlbkbmgr.exeDell AIO Printer A*** related (*** = model). Not Required at Startup
    UDell AIO Printer A920dlbkbmgr.exeSystem Tray application for the Dell Photo AIO Printer 920 that enables scan or fax functions to run directly from the printer via the buttons
    UDell AIO Printer A940dlbabmgr.exeSystem Tray application for the Dell Photo AIO Printer 940 that enables scan or fax functions to run directly from the printer via the buttons
    UDell AIO Printer A960dlbfbmgr.exeSystem Tray application for the Dell Photo AIO Printer 960 that enables scan or fax functions to run directly from the printer via the buttons
    NDell AlertDAMon.exe"Dell Alert" utility, that's supposed to make interaction with Support easier
    UDell Photo AIO Printer 922dlbtbmgr.exeSystem Tray application for the Dell Photo AIO Printer 922 that enables scan or fax functions to run directly from the printer via the buttons
    UDell Photo AIO Printer 942dlbubmgr.exeSystem Tray application for the Dell Photo AIO Printer 942 that enables scan or fax functions to run directly from the printer via the buttons
    UDell Photo AIO Printer 962dlbxmon.exeDellPhoto AIO Printer 962 Device Monitor
    NDell QuickSetquickset.exeDell taskbar icon allowing you to quickly change settings
    NDELL Webcam ManagerDellWMgr.exeDell Webcam Manager - Webcam management software provided on Dell PCs
    UDell Wireless Manager UIWLTRAYInstalled alongside Dell Wireless WLAN Card and provides additional configuration options for these devices
    NDell Wireless Manager UIwltray.exeSystem tray access to wireless LAN card configuration options
    ?DellDMIdelldmi.exePossibly part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards?
    UDELLMMKBDELLMMKB.EXEMultimedia keyboard control for Dell based PCs - only required if you use the multimedia keys
    NDellSCdellsc.exeDell Solution Center - web-based troubleshooting tools and educational offerings
    UDellSupportDSAgnt.exeDell Support Agent offers additional support and update features for your Dell computer or laptop
    UDellSupportCentersprtcmd.exe /P DellSupportCenterDell Support Center (provided by SupportSoft, Inc) is a free self-help tool for Dell users. Identifies and automatically fixes typical problems that may occur with your high-speed internet service
    UDellTouchMMKeybd.exeDell multimedia keyboard manager. Required if you use the additional keys
    UDellTouchDELLMMKB.EXEMultimedia keyboard control for Dell based PCs - only required if you use the multimedia keys
    Xdelmsbbdelmsbb.exeNCase adware
    Xdelsaapdelsaap.exeNCase adware
    ?delstartdelstart.exeReportedly part of BT ISP software - what does it do and is it required in startup?
    Xdelsubmitrundll32.exe advpack.dll, DelNodeRunDLL32 submit.exeCoolWebSearch parasite variant
    ?DelTmpDelTemp.exeAdded to the startup list after installing a Creative SoundBlaster Audigy soundcard. Deletes temporary files once an installation is complete?
    NDeltTraydeltray.exeSystem Tray access to the control panel for the M-Audio Delta 44 PCI Analog Recording Interface. Available via a desktop shortcut, Start -> Programs or Start -> Settings -> Control Panel
    XDeluxeCommunicationsDxc.exeDeluxe Communications, a SurfSideKick adware variant
    XDELXP Protocoldelxp.exeAdded by a variant of the SDBOT WORM!
    ?demondemon.exePart of the French Wanadoo ADSL extense pack. What does it do and is it required?
    XDenecaVirus salvadoAdded by the DELUZ VIRUS!
    UDepFrezfrzstate.exeDeep Freeze from Faronics Coporation. "Freezes" the current software configuration so that an a re-boot all changes made refer back to their original settings. Not required for most users - more likely to be used by system administrators, for example
    ?Description of Shortcuts*.exe* seems to be a sequence of alphanumerics that can be different, i.e., 1960F8A9, 4EBD23F5, etc. Each of these files would appear to be a shortcut, i.e., 4EBD23F5 is actually Works Calender Reminder (found via a registry search)
    XDesiredesires.exeAdult content dialler
    ?desk-top-servicedesk-top-service.exe??
    XDeskAd ServiceDeskAdServ.exeDeskAd.Service adware
    NDeskColorDESKCOLOR.EXEProvides transparent icon text backgrounds and coloured icon text
    NDeskflagDeskflag.exeDeskFlag - animated USA flag on the desktop
    XDeskMateAutoUpdateDeskMateAutoUpdate.exeDeskMates: Virtual scantily clad girls enhance your desktop. BargainBuddy adware related
    UDesksite CMAcma.exeDeskSite CMA siftware - "retrieves new content from the DeskSite Data Center"
    UDeskSlideDeskSlide.exe"DeskSlide is utility for automating wallpaper changes on your desktop"
    XDesktoprundll32.exe msconfd.dll, Restore ControlPanelAdded by the BOOKMARKER TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "msconfd.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    Xdesktopdesktop.exeAdded by the SDBOT.MD WORM!
    XDesktopDesktop.comAdded by the VB-DRN WORM!
    Xdesktopdesktop.ini.vbsIE-Title malware
    NDesktop ArchitectDATRAY.EXEDesktop theme manager available here - for managing the desktop appearance, fonts, sounds, etc
    UDesktop CalendarDesktop Calendar.exeDesktop Calendar - "Desktop Calendar is a highly customizable calendar program that turns your desktop into a traditional wall calendar, by rotating the background image on a monthly basis"
    NDesktop PlantAZARE10S.PLTVritual plant from here - this version is an Azalea, there are others so the filename may be different
    XDesktop Searchdesktop.exeiSearch "Desktop Search" hijacker
    NDesktop Service CentreDSC.exeOptusNet DSL or Dial-Up connection software
    NDesktop WeatherTHE WEATHER CHANNEL.exeDesktop Weather by The Weather Channel - provides current temperature, conditions, alerts, etc
    NDesktop Weather 3THE WEATHER CHANNEL.exeDesktop Weather 3 by The Weather Channel - provides current temperature, conditions, alerts, etc
    NDesktop Weather 3THEWEA~1.EXEDesktop Weather 3 by The Weather Channel - provides current temperature, conditions, alerts, etc
    UDesktopIconToyDesktopIconToy.exe"Desktop Icon Toy is an easy to use desktop icon enhancement tool, which allows you to make many funny but useful patterns out of your windows desktop icons"
    Ndesktopmgrdesktopmgr.exeSynchronisation manager for the cradles for the Research In Motion range of wireless handhelds, including the "Blackberry"
    XDesktopUpdaterundll32.exe MSA64CHK.dll, DllMostrarMatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder
    UDesktopXDESKTOPX.EXEA program that replaces the regular Desktop and Taskbar, and can be changed to the user's liking
    Ndeskupdeskup.exeAdds Iomega Zip drive icons to the desktop
    Xdestroyb11destroyb11.exeAdded by the DELF-KO TROJAN!
    Udetectidetect.exeiNTERNET Turbo from Clasys Ltd. "It accelerates any Windows 95/98/Me/NT/2000/XP internet connection in seconds". If you find it helps your connectivity leave it enabled
    ?detectturbodetect.exe??
    NDetectordetector.exeUSB port detector for LG scanners. Sits in the System Tray, and when it detects the scanner through the USB port, you can run the scanner software from the tray. It is not required at all, since you can use the scan software from almost any photo editing software
    UDetectorAppDetectorApp.exeRelated to Roxio MyDVD (was Sonic) DVD authoring software
    ?DevconDefaultDBREADREGAppears to be related to older Creative Soundblaster soundcards
    XDevelopment Environmentdevenv.exeAdded by the DELBOT-AH WORM!
    UDEventAgenteventagt.exeDEvent Agent Module client - part of Dell OpenManage and used for server management. Only required if you use this
    Xdevenvsmvss.exeAdded by the DEDLER-G TROJAN!
    XDevice Configuration Loadermsdvc32.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    UDevice DetectorDevDetect.exeACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically
    NDevice Detector 2DevDtct2.exeInstalled by various Olympus products, this program detects the active connection of a speech device (voice recorder, etc) to a USB port then runs specific client software used to access that device. The DevDtct2 process has a "high" priority level which can negatively impact system resources
    XDevice Managerwfxmgr.exeAdded by the RBOT.AJU WORM!
    UDeviceDiscoveryhpotdd01.exeDetection of new imaging, printing and other peripherals on HP machines such as USB printers, cameras and Bluetooth products. "This program is a non-essential process, but should not be terminated unless suspected to be causing problems"
    XDevicePathProyecto1.exeAdded by the GRUEL WORM!
    XDevicePathRoot.exeAdded by the GRUEL WORM!
    UDevicesolesvr.exeSalfeld Child Control - parental control software
    XDevicewin[path to trojan]Added by the BANKER-AEV TROJAN!
    Udevldr16devldr16.exeAssociated with some Creative Labs sound cards.  Provides audio support for DOS applications.  Not needed if you don't have those. Required if you use "Sound Play Control" and "Sound Recorder". To disable: (1) Disable via MSCONFIG (2) Start -> Settings -> Control Panel -> System -> Device Manager then disable "Creative SB16 Emulation" under Creative Miscellaneous Devices
    Udevldr16.exedevldr16.exeAssociated with some Creative Labs sound cards. Provides audio support for DOS applications. Not needed if you don't have those. Required if you use "Sound Play Control" and "Sound Recorder". To disable: (1) Disable via MSCONFIG (2) Start -> Settings -> Control Panel -> System -> Device Manager then disable "Creative SB16 Emulation" under Creative Miscellaneous Devices
    ?Devlog????
    ?Devlogdevlog.exeApparently mainboard/chipset related, by a French company called AS Media - what exactly is it, and is it required
    Xdfgfdgrergd[path to trojan]Added by the RANKY.CK TROJAN!
    Xdfgfdgrergd[path to trojan]Added by the RANKY.CK TROJAN!
    ?DGJMDGJM.exe??
    Xdgtstartdgtstart.exeDigitalNames.g adware
    Udguarddguard.exeeAcceleration Stop-Sign security software related. Previously not recommended, see here
    XDHCPsmss.exeAdded by the WINSPY.AG TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
    XDHCP Serverregsvr.exeAdded by the RBOT-PR WORM!
    XDHCP32services.exeAdded by the WINSPY.AG TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
    Ydhcpagntdhcpagnt.exeIntel DSL modem driver - leave enabled or you'll have to re-install the drivers
    ?DHNUXBDHNUXB.exe??
    Ndiagentdiagent.exeSystem Tray access for Creative Diagnostics for the Creative SoundBlaster series soundcards. Available via Start -> Programs
    XDiagnosticdiagnostic.exeAdded by the ALPHA-C TROJAN!
    XDial22dlm.exeAdult content dialler
    XDial33dlm.exeAdult content dialler
    XDialerrundll32.exe msa32chk.dllUnidentfied malware
    UDialer Controldc.exeDialer-Control. Detects and protects from premium rate p0rn diallers
    UDialer Detectdd.exeDialerDetect detects stealth installed premium rate diallers, and sounds the alarm when such a connection is being installed without you knowing it
    UDialgo SDKPhoneAnswer.exeDialgo Wave Modem ActiveX - "Telephone Answering Machine for scripting your own professional call center business scripts using a voice modem. Features Caller-ID, Wave Playback, Wave Recording, Digit Monitoring, POP3 e-mail Manipulation, Speech Recognition and Synthesis"
    XDialNetmxt32.exeAdult content dialler
    NDialog Box AssistantOSDEx.exeDialog Box Assistant from Duality Software. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders
    NDialog HelperPDDLGHLP.EXEDialog Helper from PowerDesk Pro by Ontrack. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders. Available via Start -> Programs
    XDialUp Network ApplicationRnaap.exeAdded by a variant of the SDBOT WORM!
    XDiam prlaeroqedrhg.exeAdded by the SDBOT-DEU WORM!
    ?DiamondviewDiamondview.exeManulife Financial Insurance program. Is it required at startup?
    XDIECOXcsrss.exeAdded by a variant of the ATM.GEN TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
    XDieselRecalculate.exeAdded by the LAZAR TROJAN!
    UDietKDietK.exeDiet Kazaa add-on for Kazaa Media Desktop - "removes all adware and popups, built in Download Accelerator, makes searches faster and helps produce more results"
    UDigiCellDigiCell.exeMSI DigiCell - "the most useful and powerful utility that MSI has spent much research and efforts to develop, helps users to monitor and configure all the integrated peripherals of the system, such as audio program, power management, MP3 files management and communication / 802.11g WLAN settings. Moreover, with this unique utility, you will be able to activate the MSI well-known features, Live Update and Core Center"
    XDigiDDigitalSound.exeAdware downloader
    NDigiGuideCLIENT.EXETV guide and reminder
    NDigiGuideclient01.exeTV guide and reminder
    UDigisoft AntiDialerAntiDialer.exeDigisoft AntiDialer
    UDigiSrvDigiSrv.exeRelated to camera software from DigitalDreams
    NDigital Dashboarddevgulp.exeFor Compaq PC's. Loads Digital Dashboard options
    NDigital Line DetectDLG.exeDetects whether your are plugged into a digital telephone line and displays the information graphically. Installed by Dell (and maybe others) and is included with all Connexant V.92 and Broadcom modems
    UDigital Patrol Update 5update.exeDigital Patrol - "a powerful anti trojan scanner, which detects and eliminates more than 180'000 Trojan Horses and Spywares. Digital Patrol detects viruses, trojans, worms, spyware, malicious ActiveX controls and Java applets"
    NDigital River eBotdownlo~1.exeDigital River Systems EBOT for downloading software from their site. In some cases, if you purchase software online for a download from a software manufacturer, you will be sent to this online company's site for the download after the purchase is complete. Read more here
    XDigitalNamesDigitalNamesStart.exeDigitalNames spyware variant
    NDigitalWizardISWizard.exeInstallShield's DigitalWizard - free, complete Digital Content Management Solution that makes it easy to experience digital content
    NDigitalWizard MonitordwMon.exeInstallShield's DigitalWizard - free, complete Digital Content Management Solution that makes it easy to experience digital content
    UDIGServicesDIGServicesCreated by Disney but licensed to ESPN for watching videos
    NDIGServicesDIGServices.exeCreated by Disney but licensed to ESPN for watching videos
    NDIGStreamdigstream.exeDIGStream Cache Manager - part of ESPN Motion and Disney Motion that periodically check for new videos and indication they're available in the System Tray. Starting ESPN Motion/Disney Motion starts digstream automatically
    UDimensionDimension.exeDimension - a program which lets you customize MSN messenger such as adding animated and coloured nicknames, personal toast creator, war tools (login flooder), and allows viewing and interacting with the raw MSN protocol
    UDimension4d4.exeDimension 4 - network time synchronization freeware - starts-up, adjusts the system clock, then shuts down
    XDino3dino3.exeRelated to Jurassic Park III and enables a dinosaur to walk across the screen. Also generates adverts and classified as adware as a result
    XDinstdinst.exeIMIServer/IEPlugin adware
    XDir1caKeAdded by the CAKE WORM!
    XDirect settingssdchost.exeAdded by the DAEMONI-I TROJAN!
    UDirect UpdateDUControl.exeDirectUpdate dynamic DNS updater
    XDirect X Direct3Ddxd3d.exeAdded by a variant of the SDBOT WORM!
    XDirect X Opengldxopengl.exeAdded by a variant of the RBOT-CJ WORM!
    Xdirect3d.exedirect3d.exeAdded by the CERTIF-F TROJAN!
    NDirectCDDirectCD.exeDirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
    YDirectory Opus Desktop Dblclkdopusrt.exeDirectory Opus - an advanced file manager. "Directory Opus goes beyond the simple file manager metaphor, and offers you a complete replacement for Windows Explorer and many other utility programs for handling FTP, ZIP, viewing files and images, running slideshows and more"
    Xdirects.exedirects.exeAdded by the BEAGLE.O or BEAGLE.R or BEAGLE.S or BEAGLE.T WORMS!
    UDIRECTVDSLDirectvdsl.exeStarts DirectTV DSL modem at boot up. Can also be started manually
    XDirectXddhelp32.exeAdded by the BIONET.318 TROJAN! Note - not the DirectX helper which is ddhelp.exe
    XdirectxDirectx.exeAdded by the SDBOT.D TROJAN!
    XdirectxSqlexploit.exeAdded by the SDBOT.D TROJAN!
    XDirectXDirectX.exeAdded by the BLAXE or LOGPOLE WORMS!
    XdirectxNTCmd.exeAdded by the SDBOT.D TROJAN!
    XdirectxPipeCmd.exeAdded by the SDBOT.D TROJAN!
    XDirectX 32directx32.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    XDirectX For Microsoft Windowsdtxservice.exeAdded by the PROGENT TROJAN!
    XDirectX for Microsoft WindowsFservice.exeAdded by the PRORAT TROJAN!
    XDirectX for Microsoft WindowsSservice.exeAdded by the PRORAT TROJAN!
    XDirectX For Microsoft? Windowsfservice.exeAdded by the PRORAT-P TROJAN!
    XDirectX shell driver[path to trojan]Added by the MARKTMAN-B TROJAN!
    XDirectx Startup Driversdirect.exeDetected by PCTools as the RBOT.UXL WORM! See here
    XDirectX Video Driverdxterm5.exeAdded by the WILAB-A TROJAN!
    XDirectX64DirectXset.exeAdded by the BROWNEY.A WORM!
    XDirectX9direct3d.exeDetected by Kaspersky as the AGENT.EDW TROJAN! See here
    XDirectX9 Diagdx9diag.exeAdded by the RBOT-ALT WORM!
    UDirkeyDirkey.exeDirkey - small utility that allows you to bookmark up to 9 folders by using the Ctrl+Alt+1..9 shortcut keys in an Open/Save File dialog or in Windows Explorer. After this the Ctrl+1..9 shortcut keys can be used in the same or another window to go to any of the 9 bookmarked folders 
    ?Disable EHCInousb20.exe??
    NDisc DetectorCtNotify.exeFor Creative sound cards. Detects when you insert a CD, DVD, etc
    ?disc detectorqnetquestnotifty.exe??
    ?discovegdiscoveg.exe??
    ?DISCoverDISCover.exeRelated to DISCover Drop from Digital Interactive Systems Corporation. What does it do and is it required?
    NDiscoverDeskshopDeskshop.exeDiscover Deskshop - single use "virtual" credit card
    UDiscUpdateManagerDiscUpdMgr.exeDisc Update Manager for Digital interactive's DISCover Console. Provider of on-demand video games
    NDiscUpdateManagerDiscUpdateMgr.exeDISCover from Digital Interactive Systems Corporation Inc. "The company?s patented Drop ?n? Play technology provides a simple, console-like experience when playing PC titles allowing for seamless play of CD/DVD-based games while its unique Parental Control system incorporates ESRB ratings to help users limit access to younger players"
    UDiscWizardMonitor.exeDiscWizardMonitor.exeSeagate DiscWizard - hard disk utility for Seagate's SATA and PATA (IDE) drives
    XDisk Checkchkdsk32.exeAdded by the IM TROJAN!
    UDisk CleanerDiskCleaner.ExeHard disk management part of TuneUp Utilities from TuneUp Distribution GmbH
    XDisk Defragmentation Loaderpmsvcr.exeAdded by a variant of the IRCBOT TROJAN!
    XDisk Essensial Toolsdetsvc.exeAdded by a variant of the IRCBOT TROJAN!
    XDisk Keeper[path to trojan]Added by the SMALL-VE TROJAN!
    XDisk KeeperSECURITY.EXEDaosearch adware
    XDisk Managerdiskver.exeAdded by the RBOT.AQT WORM!
    XDisk Master[trojan name]Added by the DISTER TROJAN! - a spam relayer
    XDisk Panel Configurationdpcsvc.exeDetected by PCTools as the IRCBOT.BSQ TROJAN! See here
    XDisk Panel Setupnpcsvc.exeAdded by a variant of the IRCBOT TROJAN!
    XDiskCheckmsdarkend.exeAdded by an unidentified WORM or TROJAN!
    NDiskeeperSystrayDkIcon.exeDisKeeper defragmentation software - can be started manually
    Xdiskinfdiskinf.exeAdded by the CRYPTER.A TROJAN!
    ?DISKMON.EXEDISKMON.EXE??
    NDisknagdisknag.exeDell program that reminds you to make your  backup diskettes
    XDiskstartCode.exeAdult content dialler
    XDiskstartcat.exeMS-Connect dialler
    XDiskstarthit.exeAdult content dialler
    XDiskstartSnt.exeAdult content dialler
    UDisk_MonitorDisk_Monitor.exeMulti-media, Smartmedia, Compact Flash card reader for reading digital camera cards. Device is recognised as internal USB disk drive. Necessary if camera cards are to be recognised as soon as they are inserted into the reader
    Xdisnisadisnisa.exeAdded by the DORF-AE WORM!
    XDispatcherdispatcher.exeAdded by the DLOADR-AS TROJAN!
    UdisplayThe_Eye.exeComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself
    XDisplay Driverscssrs.exeAdded by the AGOBOT.FX WORM!
    NDisplay Settingshptasks.exeAllows for the adjustment of the display for LCD screen, CRT Monitor and TV output on HP computers
    UDisplayFusionDisplayFusion.exeDisplayFusion from Binary Fortress Software - "is a fantastic application that can make your dual monitor (or triple monitor or more) life much, much easier! From allowing you to use a different wallpaper on each monitor, to integrating with Flickr for image searching, to providing hotkeys for managing your application windows"
    NDisplayTrayIconTrayIcon.exeSystem Tray access to display properties for ABIT graphics cards. Unless you change your desktop resolution, etc regularily use Control Panel -> Display
    UDisspydisspy.exeDisspy spyware detection and removal software
    NDistiller Assistant 3.01DISTASST.EXEFrom Adobe. Creates PDF universal files for Acrobat Reader. Available via Start -> Programs
    XDistributed File SystemDfsvc.exeAdded by the MYFIP.A or MYFIP.K WORMS!
    XDistributed File Systemkernel32dll.exeAdded by the MYFIP-C or MYFIP.K WORMS!
    XDistributed File Systemblade.exeAdded by the MYFIP.AC WORM!
    UDistributed File Systemwin.exeAdded by the MYFIP.AB WORM!
    Udistributed.net clientDNETC.EXEDsitributed computing projects client from Distributed.net where numerous computers are used to share a projects workload - similar to SETI@Home and Folding@Home. Also prone to being distributed by viruses
    YDitdit.exe"Drive Icon and Label Utility" - assigns drive icons and names to flash memory cards. Required, otherwise the drives aren't found
    XDitdit.exeAdded by the LAZAR-A TROJAN! Note - this is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    NDiTask.exeDiTask.exeAssociated with an Eicon Networks ISDN or ADSL modem. System Tray icon which shows you the status of your lines (free, occupied with incoming or outgoing call). Available via Start -> Programs
    ?Divamon.exeDivamon.exeAssociated with an Eicon Networks Diva ISDN or ADSL modem - what does it do and is it required?
    Xdivxdivxenc.exeAdded to the SPBOT.B TROJAN!
    XDivxcodll.exeAdded by the GRAVEBOT-A TROJAN!
    XDivX MediaPlayer 7.0Dr.DivX.exeAdded by the ALADINZ.G TROJAN!
    XDivX PlayerDivXPlayer.exeAdded by a variant of the RBOT WORM!
    XDivX UpdaterDivX.ExeAdded by the NALDEM TROJAN or MASTAK VIRUS!
    XDIVX Video PlayerDIVXPloyer.exeAdded by an unidentified WORM or TROJAN!
    XDivx4 codecdevldr32.exeAdded by an unidentfied VIRUS! Note - this is not the legitimate Creative Labs devldr32.exe file
    NDJREGFIXregedit /s c:hpdjregfix.regDJRegFix showed up first in WinME as a "clever" way to ensure that all Hewlett-Packard DeskJet printers actually worked with WinME - since most were having major problems. This "utility" adds the functionality and compatibility HP forgot to add in its WinME drivers
    ?DJSNetCNDJSNetCN.exe"Symantec Licensing Detect Internet Connection", part of Norton Antivirus. What does it do and is it required?
    Xdjtopr1150.exedjtopr1150.exeWebRebates adware
    XdKerneldKernel.exeAdded by the DECOY-A WORM!
    YDkServiceDkService.exeFrom Executive Software's Diskeeper defragmenting utility - a replacement for Windows Disk Defragmenter. It's recommended to leave this enabled, otherwise you could have problems starting it manually.
    XDKTimedktime.exeAdded by the LUNII TROJAN!
    XDkware lptt01dkware.exeRapidBlaster variant (in a "DonkeySoft" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
    XDkware ml097edkware.exeRapidBlaster variant (in a "DonkeySoft" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
    ?dkzzixmdkzzixm.exe??
    Ydlatfswctrl.exeDrive letter access to a UDF packet writer for CD-RW - from HP, Veritas an others. Similar to Roxio's DirectCD and does the same thing. From HP - "This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"
    UDLADLACTRLW.EXESonic CD/DVD burning applications
    NDlaTrayDlatray.exeSystem Tray access to DLA - Drive letter access to HP's and Veritas' version of DirectCD. Does the same thing as DirectCD. From HP - "This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"
    Ndlbcservdlbcserv.exeRelated to Dell Photo Printers and provides additional configuration options for these devices
    YDLBTCATSrundll32 [path] DLBTtime.dll, _RunDLLEntry@16Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    YDLBUCATSrundll32 [path] DLBUtime.dll, _RunDLLEntry@16Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    YDLBXCATSrundll32 [path] DLBXtime.dll, _RunDLLEntry@16Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    YDLCCCATSrundll32 [path] DLCCtime.dll, _RunDLLEntry@16Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll). If you use the 964 printer, Dell recommends leaving dlcctime.dll in place as it fixes compatibility issues on some Dell systems. If you receive an error message on system startup that reads: "Error in C:WINDOWSSystem32spooldriversW32x863DLCCtime.dll Missing entry: RunDLLEntry" Dell offers help here
    Udlccmon.exedlccmon.exeDell Photo AIO Printer 924 device monitor
    YDLCDCATSrundll32 [path] DLCDtime.dll, _RunDLLEntry@16Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    Udlcdmon.exedlcdmon.exeDell Photo AIO Printer 944 device monitor
    YDLCFCATSrundll32 [path] DLCFtime.dll, _RunDLLEntry@16Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    YDLCGCATSrundll32 [path] DLCGtime.dll, _RunDLLEntry@16Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    Udlcgmon.exedlcgmon.exeDell Photo AIO Printer 810 device monitor
    YDLCICATSrundll32 [path] DLCItime.dll, _RunDLLEntry@16Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    Xdlcipscldcpavss.exeAdded by the MAILBOT-CB TROJAN!
    YDLCJCATSrundll32 [path] DLCJtime.dll, _RunDLLEntry@16Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    Udlcjmon.exedlcjmon.exeDell Photo AIO Printer 964 device monitor
    YDLCQCATSrundll32 [path] DLCQtime.dll, _RunDLLEntry@16Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    Udlcqmon.exedlcqmon.exeDell Photo AIO Printer 964 device monitor
    Udlcqmon.exedlcqmon.exeDell Photo AIO Printer 964 device monitor
    YDLCXCATSrundll32 [path] DLCXtime.dll, _RunDLLEntry@16Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    Udlcxmon.exedlcxmon.exeDell Photo AIO Printer 926 device monitor
    Xdlderdlder.exeAdvertising spyware. Considered to be one oft the worst - even creating a fake "explorer.exe" file. Can be installed via versions of "Grokster", "Lime Wire" and "KaZaA" amongst other file-sharing utilities (see here). Reported in the past as a virus
    XDlDir1caKeAdded by the CAKE WORM!
    ?DLForcerExeDLForcerEXE.exe??
    NDLF_00000B00Vcdlf.exeKnown to cause problems with "Out of memory" errors (see here). Otherwise, it's purpose is unknown
    NDLGDLGCHBW.exeBackweb part of Data LifeGuard - diagnostic tools for Western Digital's series of hard drives. Automatically detects an internet connection and downloads any available updates
    NDLHelperEXEWATCH.exeDownload helper distributed with some software that allows the software installation to redirect download locations. Not required once the installation is finished
    XDLHelperEXE.exeN/ADownloader for Microgaming/Casino software - stealth installed
    Xdlhostdlhost.exeAdded by the EXPHOOK-A TROJAN!
    XDLINK dfe drivers for Windows NTwindfe.exeAdded by the RANDEX.AK WORM!
    UDLink System Traydlnetst.exeRelated to D-Link DGE-530T PCI card for servers and workstations
    XDlitedllmanager.exeAdded by the WOOTBOT.DN WORM!
    XDll Boot Loader on Startup (do not remove this)[various filenames]Added by an unidentified TROJAN!
    XDll Linksvchoist.exeAdded by the AUTOSKY WORM!
    XDll Linksvchost.exeAdded by the AUTOSKY WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Documents and SettingsFavourites folder
    XDLL Managerdllmngr32.exeAdded by a variant of the RBOT WORM!
    XDLL Service Manager[path to worm]Added by the RPCBOT.F TROJAN!
    Xdll services[random filename].exeAdded by a variant of the SDBOT WORM!
    XDLL32dllmem32.exeAdded by the KWBOT.E WORM!
    XDLL32dllhost.dllAdded by the SUCLOVE.A WORM!
    XDllCacherv2dllcachev2.exeAdded by the LATEDA TROJAN!
    Xdllcvss[random filename]Added by a variant of the SLAPER TROJAN!
    Xdlldmtdlldmt.exeAdded by a variant of the CRYPTER.C TROJAN!
    XDllExecutable[path to file]Added by the VB-SP WORM!
    Xdllhelpdllhelp.exeAdded by the STARTPAGE.DQ hijacker
    Xdllhelpdllhlp.exeAdded by the Downloader-HI TROJAN!
    XDLLHostdllhst.exeAdded by the DELBOT-AC WORM!
    Xdllhostxp.exedllhostxp.exeBrowser hijacker and adware downloader
    XDllLoaderlssas.exeAdded by the JE WORM!
    XDlloadkiller.exeAdded by the KILLAV-FK TROJAN!
    Xdllregdllreg.exeAdded by the CRYPTER.A TROJAN!
    XDLLService32dllsvc32.exeAdded by the AGOBOT.VX WORM!
    XDLLUPDATE32dllupdate32.exeAdded by the AGOBOT.IA WORM!
    NDLM.exeDLM.exeIGN Download Manager has become a requirement for downloading files through FilePlanet.com. It is based on Internet Explorer and it installs through an ActiveX-plugin, hence Internet Explorer must be installed beforehand and downloads has to be initialized through that browser
    NdlmMgrAdobeDownloadManager.exeAdobe Download Manager - "can prevent you from having to start from the beginning should your download process be interrupted, and it offers a level of service not possible
    UDLPSPDLPSP.EXEDell laser printer status monitor
    Xdlsp2mxdlsp2mx.exeAdded by the MPB-B DIALER! An uninstall option can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as "dlsp2mx"
    ?DLTdlt.exe??
    Xdlucadluca.exeAdult content dialler - see here
    Xdlucadluca.exeAdded by the DLUCA.C TROJAN!
    Xdluxdedluxde.exeAll-In-One-Telcom (adult content dialler) variant
    XDluxjpcnfrm.exeAdded by the DLUCA.D TROJAN!
    XDm Hrlpns.exeAdded by the IRCBOT.WORM.61673 WORM!
    XDM mgrdm_mgr.exeAdded by the JITTAR TROJAN!
    Xdm***.exe [* = random char]dm***.exe [* = random char]Wareout - malware masquerading as a spyware and dialer remover
    NDMASchedulerDMAScheduler.exeRelated to DigitalMedia Plus Archiver. This program is non-essential process to the running of the program, but should not be terminated unless suspected to be causing problems
    XDMCdmc.exeAdded by Trojan-Downloader.Win32.Dluca.bv TROJAN!
    UDMHotKeyDMLoader.exeHotKey access to the Samsung Display Manager on laptops and ultra-mobiles that support it - such as the M55 and Q1
    NDMILDRdmildr.exePart of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. Available via Start -> Programs
    NDMISLDMISL.EXEDMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See here for more information
    NDMISLAPPDMISLAPP.exeDMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See here for more information
    ?dmjaydmjay.exe??
    Xdmloaderdmloader.exeAdded by a variant of the RBOT WORM!
    XDmsvc32Dmsvc32.exeAdded by the AGOBOT.ABU WORM!
    Xdmtdlldmtdll.exeAdded by a variant of the CRYPTER.C TROJAN!
    UDmwClientdmwclient.exeDMW "anti-cheating" software for online gaming
    UDMXLauncherDMXLauncher.exePart of Dell's Media Experience, a multimedia suite which offers the user functionality to organise and play music and digital video files
    Xdm[3 random letters].exedm[3 random letters].exeAdded by the RUINDEM TROJAN!
    XDM_serverdmserver.exeComet Cursor adware
    Xdm_service[path to file]Added by the MITGLIEDER.P TROJAN!
    Xdnamd140113.a.Stub.EXEAdded by the STUB_A TROJAN!
    XDnarDnar.exeUnknown, except that it is not necessary. Tends to phone home a lot. DMI related - see here
    YDNE Binding Watchdogrundll dnes.dll, DnDneCheckBindingsDeterministic NDIS Extender (DNE). DNE is an NDIS-compliant module which appears to be a network device driver to all protocol stacks and a protocol driver to all network device drivers. Part of Gilat Communications internet satellite systems. Required if you have this system. Also installed by Winproxy - a proxy program for sharing internet connections through one computer. Required if you want it to work
    YDNE DUN Watchdogrundll dnes.dll, DnDneCheckDUN13Deterministic NDIS Extender (DNE). DNE is an NDIS-compliant module which appears to be a network device driver to all protocol stacks and a protocol driver to all network device drivers. Part of Gilat Communications internet satellite systems. Required if you have this system. Also installed by Winproxy - a proxy program for sharing internet connections through one computer. Required if you want it to work
    XDNHelper32DNHlp32.exeAdded by an unidentified WORM or TROJAN!
    XDNSmc-58-12-0000080.exeShorty adware - also detected as the AGENT.FD TROJAN!
    XDNSmc-58-12-0000093.exeShorty adware - also detected as the AGENT.FD TROJAN!
    XDNSmc-110-12-0000079.exeShorty adware - also detected as the AGENT.FD TROJAN!
    XDNSmc-58-12-0000120.exeShorty adware - also detected as the AGENT.FD TROJAN!
    XDNSmc-58-12-0000140.exeShorty adware - also detected as the AGENT.FD TROJAN!
    XDNS[worm filename]Added by the CQG WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Common Files folder
    XDns Resolverdnsrslve.exeAdded by the RBOT-WS WORM!
    XDNS Servicednsresolver.exeAdded by the RBOT-PQ WORM!
    XDNS Servicednssvc.exeAdded by the DELBOT-Z WORM!
    ?DNS2GoClientdns2goclient.exeDNS2Go is a Domain Name System that will make your computer accessible anytime, anywhere by associating a domain name of your choice to your currently assigned IP address. Is it required?
    NDNS7reminderEreg.exe Ereg.iniScanSoft (Nuance) Dragon NaturallySpeaking registration reminder. Version 7
    XDNSCacheBoostdnsping.exeAdded by the DNSBUST-A TROJAN!
    Xdnscleanerdnscleaner.exeCoolWebSearch parasite variant
    Xdnsednse.exeWinAntiVirus Pro 2007 and Privacy Protector misleading security software - not recommended, see here
    ?DNXVCdnxvc.exe??
    Xdocdoc.exeAdded by the AGOBOT-BJ WORM!
    XDocTorDoctor.exeAdded by the DOTOR.A WORM!
    NDocuMagix InitPWATCH.EXEPaperMaster is an application for the PC designed to automate the process of organizing, archiving, and retrieving digital versions of files. Start manually if needed
    UDocument Managerdocmgr.exeWave Systems Corp. Document Manager - "provides secure storage and management capabilities for file and folder level encryption"
    XDoggy StyleMsPMSPSd.exeAdded by the SDBOT-AAP WORM!
    XDOGStartGSDOGST.EXEAdded by an unidentified VIRUS, WORM or TROJAN! A possibility is a trojan known as PENIS
    ?Doingdoing.exe??
    Xdoit.exedoit.exeAdded by the FORBOT-EK WORM!
    XDomain Name Resolve Servicednsresolver.exeAdded by the KIMAN.A WORM!
    XDomPlayer Servicewakeservice.exeDomPlayer adware
    UDon't Panicdontpanicdemodp.exe30-day trial version of Don't Panic privacy software from Panicware. "Clean up Internet tracks and quickly hide personal documents with this privacy suite."
    UDon't Panic Pop-Up Stopperdpps2.exePop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group
    UDon't Panic!DP.EXEDon't Panic! privacy software from Panicware. "Clean up Internet tracks and quickly hide personal documents with this privacy suite"
    UDopusdopus.exeDirectory Opus - a file manager from GPSoft
    NDoroServerDoroServer.exeDoro PDF Writer from The SZ Development. All what you need for creating pdf files
    Xdosdos64.exeAdware downloader trojan
    XDos Prompt Loadercygwin.exeAdded by the SDBOT-VV WORM!
    ?Dosbat????
    XDot1XCfgDot1XCfg.exeDetected by PCTools as Maxfiles adware - see here
    UDoubleDesktopdd.exe"DoubleDesktop is a smart and elegant system tray utility that effectively doubles the width of your Windows desktop"
    NDoUWantItduwi.exeDoUWantIt - online shopping assistant. Start it manually
    XDowmingzuDowmingzu.dll.vbsAdded by the SOLOW-E WORM!
    Xdownhlp32.exeAdded by the DLOADER.BG TROJAN!
    Xdown[trojan filename]Added by the Small-QJ TROJAN!
    UDown2HomeDown2Home.exeDown2Home - "monitors your ADSL/Cablemodem/Dialup traffic and provides you with usefull statistics about the amount of data your PC has transferred"
    NDownload Accelerator Manager Free Editiondam.exeDownload Accelerator Manager Free Edition from Tensons Corp
    NDownload Accelerator Plus 5.0DAP.exeDownload Accelerator Plus from Speedbit. Download manager for resuming downloads, amongst other features. Available via Start -> Programs. Note that the free version is adware based
    XDownload PlusDownloadPlus.exeDownloadPlus adware
    NDownload WonderDownloadWonder.exeDownload Wonder from Forty Software. Download manager for resuming downloads, amongst other features
    NDownloadAcceleratorDAP.EXEDownload Accelerator Plus from Speedbit. Download manager for resuming downloads, amongst other features. Available via Start -> Programs. Note that the free version is adware based
    XDownloadLegalMusicrundll32.exe MSA64CHK.dll, DllMostrarMatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder
    XDownloadMP3rundll32.exe MSA64CHK.dll, DllMostrarMatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder
    XDownloadWaredw.exeDownloadWare adware
    XDownloadWare EngineDwe.exeDownloadWare adware
    XDownxzDownxz.batAdded by the MYDOOM.W WORM
    NDPAgntDPAgnt.exedigitalPersona fingerprint scanner
    UDPASDPASNT.exeDefenderPro AntiSpy - spyware remover
    UDPASUpdateDPASAutUpdate.exeAutomatic updates for DefenderPro AntiSpy - spyware remover
    UDPASUpdateDPASAutoUpdate.exeDefender Pro Antispy
    YDpcnavdpcnav.exeDirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access
    NDPConfigDPConfig.exeCompuware DevPartner Studio Configuration Utility, a tool for software developers - System Tray access to configure the utility's analysis. Not required at startup, can be launched from the Start Menu programs group when needed
    Xdpcproxydpcproxy.exeAdded by the GOLDENP-A TROJAN!
    YDPCProxyLoadOnStartupdpcstart.exeDirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access
    YDpcstartdpcstart.exeDirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access
    Xdpidpi.exeDelfin Media Viewer or "Promulgate" adware
    Xdpnsvr32dpnsvr32.exeAdded by the AOLPASS-B TROJAN!
    Udpps2dpps2.exePop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group
    Xdpsdps.exeSmartestSearch parasite - poses as a foistware, bogus adware/spyware remover called "scumware-remover"
    Ndptrackerdptracker.exeCamTrack webcam software that enhances the way people video chat
    UDpUtilTEDTray.exeMain executable for TOSHIBA DualPoint Utility Main Module. It is a system tray icon program that provides configuration options for dual pointing device
    NDrag'n'Drop_AutolaunchAutolaunch.exeIomega HotBurn - CD-RW burning software
    ?DragDropDragDrop.exe??
    NDragnDrop_AutolaunchAutolaunch.exeIomega HotBurn - CD-RW burning software
    XDRam Monitor 23tskman3.exeAdded by a variant of the RBOT WORM!
    XDRam prmaessor[random filename]Added by the RBOT.CSG WORM!
    XDRam prosesor[random filename]Added by the SPYBOT.EE WORM!
    XDRam prosessor[random filename]Added by the RBOT.CSG WORM!
    XDRam prosessorplscd.exeAdded by the RBOT.CYA WORM!
    XDRam prosessorHWAPI.exeAdded by a variant of the RBOT WORM! Note - this is not the McAfee HackerWatch process which has the same filename
    XDRam prosessorWindowsUpdate.exeAdded by the RBOT-BBZ WORM!
    XDRam rar procwinupdaterar.exeAdded by a variant of the IRCBOT TROJAN!
    XDRam rare procupdaterarwin.exeAdded by the RBOT-GQW WORM!
    XDRan posessorDAP.exeAdded by a variant of the SDBOT WORM!
    XDrCacheMSTDC.EXEAdded by the JM TROJAN!
    Xdreamsserver.exeAdded by a variant of the SDBOT WORM!
    XDrefIWSysDrefIWv2.exeAdded by the DREF-C WORM!
    XDrefIWSysDref.exeAdded by the DREF-D WORM!
    ?dregfixph_finder.exe??
    NDrgToDscDrgToDsc.exePart of Roxio EasyCD Creator 6.0 - places the Roxio Drag-to-Disc icon in you system tray. "Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically". Not required for Roxio to work properly
    ?dried.exedried.exe??
    NDriveCleaner 2006 FreeUDC2006.exeDriveCleaner is a security assesment tool which gives exaggerated reports of security and privacy risks on a computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported risks
    XDriveCleaner FreeUDC.exeDriveCleaner misleading security program - not recommended, see here
    UDriveIconsDriveIcon.exeDrive Icons from Realtek - shows a specific icon for each card type for their card reader controllers
    UDriveLEDOODLed.exeO&O DriveLED - hard disk monitoring and crash prevention
    XDrivergbot.exeAdded by the JUNTADOR.K TROJAN!
    XDriver32Scam32.exeAdded by the SIRCAM WORM!
    XDriverChecksvchost.exeAdded by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a C:DriverLoad folder
    XDriverDBsvcmdx32.exeAdded by the BERPI TROJAN!
    XDriverLoadsvchost.exeAdded by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a C:DriverLoad folder
    UDriverMagicLogondmschedule.exePart of DriverMagic - "the easiest way to locate device drivers"
    XDriverModulecsrnvrt.exeAdded by the IRCBOT.I TROJAN!
    XDriverPathsystem32.exeAdded by the PRORAT-S TROJAN!
    XDrivers for Internet Exploreraccesweb.exeAdded by freewebs.com hijacker!
    NDriveSelectdriveselect.exeDVD X Copy XPress by 321 Studios. Creates a pop-up at Windows startup that asks for the DVD drive to be selected. Available via Start -> Programs
    Udrkly16jrundll32.exe drkly16j.dll, ServiceCheckKidsWatch Time Control parental control software
    UdRMON SmartAgentSmartAgt.exePart of the network monitoring program group for 3Com NIC cards. See here for more info
    Xdrmsrv32stmhosts.exeAdded by the AGENT.AGWU TROJAN!
    XdrmuW95Mm.exeHomepage hijacker installing a toolbar: http://tdko.com/. Lop.com in disguise
    XDrmupgdsDrmupgds.exeDetected by PCTools as Maxfiles adware - see here
    Xdrocherd.exeAdult content dialler
    XDropSpam Lifestyledslifestyle.exeDropspam adware
    Xdrvddll.exedrvddll.exeAdded by the BEAGLE.AP WORM!
    XDrvddll_exedrvddll.exeAdded by the BEAGLE.X WORM!
    UDrvIconDrvIcon.exe"Vista Drive Icon changes the drive icons shown in Windows "My Computer", to a nearly Vista drive icon, showing the drive's free space with a smooth colored horizontal bar"
    ?DrvListnrDrvListnr.exeAnalog Devices SoundMAX soundcard related. What does it do and is it required?
    Udrvlsnrdrvlsnr.exeCompaq/ADI SoundMAX integrated digital audio controller related. May solve a problem if your sound cuts out unexpectedly
    UDrvMon.exeDrvMon.exeAlcor drive monitor software
    Xdrvnetwdrvnetw.exeAdded by the BROGGER-B TROJAN!
    Xdrvr32hdrvr32h.exeAdded by an unidentified VIRUS, WORM or TROJAN!
    Xdrvrmanagerdrvrquery32.exeAdded by the BOOHOO WORM!
    Xdrvsys.exedrvsys.exeAdded by the BEAGLE.W WORM!
    Xdrvsyskithidr.exeAdded by the BAGLE.HR WORM!
    Xdrvupdrundll32 ..drvupd.infHijacker - drvupd.inf file installs a "searchforge.com" hijack
    Xdrv_st_keyhidn.exeAdded by the BEAGLE.FF WORM!
    XDrWatsondrwatson_.exeAdded by the LOHAV-S TROJAN!
    XDrWatsondrwatson_32.exeAdded by the LOHAV-S TROJAN!
    XDrWeb AntivirusDRWEBAV.EXEAdded by an unidentified WORM or TROJAN!
    YDrwebschedulerDrwebscd.exeDrWeb antivirus related - scheduler that allows you to manage an automatic launch of applications, in particular the antivirus scanner or the update subsystem
    XDR_SDR_S.exeAdShooter adware
    Xdsds.exeAdded by the SPYMON TROJAN!
    UDS Clockdsclock.exeDigital desktop clock including synchronization with atomic servers - see here
    Xdsadsa.exeHomepage hijacker - redirecting to downseek.com
    XDSAcass[path to file]Added by the RANKY.M TROJAN!
    Xdsadlsa14dsakfsak14.exeAdded by the ONLINEG-P TROJAN!
    XDSBDSB.exeEnergyPlugin adware
    Udscactivatedsca.exeDell Support Agent offers additional support and update features for your Dell computer or laptop
    Xdsdzz.exeAdded by the RBOT-FOX WORM!
    NDSentryDSentry.exeAnti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching, they decided to implement an anti-spyware service. Run manually before installation starts
    XDsidp-******.exeAdded by an unidentified adware where ****** are random characters
    XDsidp-him.exeAdded by the MULTIDR-AH TROJAN!
    XDskcompatDskcompat.exeAdded by the GEMA TROJAN!
    UDSKEYDsKey.exePart of PC PhoneHome - "secretly sends an invisible email message to an email address of your choice containing the physical location of your computer every time you get an Internet connection". Security software from Brigadoon Security Group for tracking down lost/stolen computers
    XDSKEY[path to trojan]Added by the STARTER-G TROJAN!
    NDSL Monitorspdstrm.exeComes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
    YDSLagentexeDSLagent.exeUsed in conjunction with USB connected ADSL modems from Eicon Networks (as used by BT for its Broadband internet service for example). Required for a permanent ADSL connection
    Ydslmondslmon.exeSagem DSL modem related. Apparently needed to detect the modem
    UDSLSTATEXEdslstat.exeSystem tray connection status for ADSL modems from Eicon Networks (as used by BT Broadband for example)
    XDsmSerdsm.exeAdded by the SERFLOG.B WORM!
    XDsmSermsmpatch.exeAdded by the SERFLOG.B WORM!
    XDsmSersvosm.exeAdded by the SERFLOG.B WORM!
    XDsmSersysup.exeAdded by the SERFLOG.B WORM!
    XDsplObjectswindspl.exeAdded by the BEAGLE.DN WORM!
    XDSSdssagent.exeDSSAgent by Br?derbund - spyware. Sends encrypted emails about the system back to the originators of the program. Also a resource hog. See here for more info
    XDSS[path to trojan]Added by the DSSDOOR-C TROJAN!
    XDSServicedmrss.exeAdded by the AGOBOT-XX WORM!
    ?DSSSGENSdssagens.exe??
    Xdstiosysplsitctl.exeAdded by the MAILBOT-BX TROJAN!
    XDSystemDriverwindrv.exeAdded by the DELF.WG TROJAN!
    UDT HPWDTHtml.exeDisplay Tune from Portrait Displays, Inc. - "is the perfect software utility to initially set-up and adjust your display to achieve its optimum performance. All adjustments are made through a simple graphical user interface and the user is guided, step-by-step, through the entire initial tuning process." Also licensed and renamed by manufacturers such as Gateway and HP
    NDU MeterDUMETER.EXEHagel Technologies internet bandwidth monitor
    UDualCoreCenterStartUpDualCoreCenter.exeUnified control center for overclocking both the graphics card and the CPU, but for the program to have its full functionality you must have an MSI mainboard with a CoreCell chip
    Xduckduck.exeAdded by the AGOBOT-AVG WORM!
    NDulux WeatherShield WeatherDeskweather.exeDulux WeatherShield WeatherDesk - latest weather information from across Australia
    XDumeter Servicesdumeter.exeAdded by the SDBOT-AEQ WORM!
    Xdumprepspoolc.exeDetected by Kaspersky as a variant of the AGENT.CXF TROJAN!
    Ndumprep 0 -kdumprep 0 -kUsed in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
    Ndumprep 0 -udumprep 0 -uUsed in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
    XDUN_SERVICES3dun3.exeAdded by the SOKIRON TROJAN!
    XDuweculeyyujixit.exeAdded by the SDBOT.BRP WORM!
    XDuwee wong CerbonCirebons.exeAdded by the BHARAT.A WORM!
    Ndvd43DVD43_Tray.exeDVD43 is "a small tool that integrates into Windows and overrides CSS copy-protection found on DVD movies"
    UDVD43DVD43.exeDVD43 is a small tool that overrides CSS copy-protection found on DVD movies
    Xdvd98windvd98.exeAdded by the CULT.P WORM!
    UDVDBitSetDVDBitSet.exeDVD+RW Drive/Disc Compatibility Setting. Installed with HP DVD+RW drives to enhance compatibility with existing readers. You can also set a DVD+RW default drive write mode which is always used
    ?DVDCheckDVDCheck.exeRelated to an Intervideo program. What does it do and is it required in startup?
    XDvdcompatDvdcompat.exeAdded by the GEMA TROJAN!
    NDVDLauncherDVDLauncher.exePart of Cyberlink's Power Cinema - allows you to play DVDs upon insertion
    NDVDSentryDSentry.exeAnti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching, they decided to implement an anti-spyware service. Run manually before installation starts
    NDVDTrayDVDTray.exeHP CD/DVD Tray icon installed with the DVD writer software. Periodically checks for new drive firmware
    NDVDUpgradeDVDUpgrd.exeMicrosoft program to upgrade your DVD decoder program - see Q306331. Available via Start -> Programs
    NDVDXGhostDVDGhost.EXEDVD Ghost - "utility to make your software DVD players and DVD copy/backup softwares restriction-free, and copy/backup DVD to hard disk"
    UdvHighMemcfgmng32.exeRelated to PureSight PC - designed to offer maximum flexibility and choice as families manage their internet use
    YDvp95Dvp95.exeScan engine for F-Secure and Command antivirus software based on the F-Prot AntiVirus engine
    Ydvpapi9xDVPAPI9X.exeCommand AntiVirus for Windows 95/98/Me
    YDvpInitExeDvpinit.exeCommand Antivirus related
    YdvprptDvprpt.exeCommand Antivirus related
    Xdvraudiodvraudio.exeAdded by a variant of the CRYPTER.C TROJAN!
    Xdvsfssfbsfsdrs.exeAdded by the SDBOT-QA WORM!
    UDVSyncdvsync.exeDVSync is the program that allows you to synchronize your daVinci's PDA's data with your Personal Information Manager on the PC
    XDvVideo32dvvid32.exeDetected by Trend Micro as the TINY.FD TROJAN! See here
    XDvxwsxsvc.exeDelfin Media Viewer or "Promulgate" adware variant
    Xdwdw.exeDownloadWare adware
    NDW4Weather.exeDesktop Weather
    NDW4DesktopWeather.exeDesktop Weather 4 by The Weather Channel - provides current temperature, conditions, alerts, etc
    UDWHeartbeatMonitorDWHeartbeatMonitor.exeDWHeartbeatMonitor.exe is installed alongside the Weather.com instant messaging utility. This is a non-essential process. Disabling or enabling this is down to user preference
    NDwlClientsupport.exeDownload manager for Dell support alerts
    YDWQueuedReportingdwtrig20.exeRelated to System Event Notification Services from Microsoft. Required for Efficient Mobile Network Computing
    NdwStartFireWall.exeThe Shield firewall from pcsecurityshield.com. Not recommended by some (see here) and there are better free alternatives out there such as Zone Alarm
    XDW_Startrwwnw64d.exeIdentified as a variant of the AdWare.Win32.ZenoSearch.am malware
    XDxsys*.exe [* = random number]Added by the DEXTER.A WORM!
    XDx8compatDx8compat.exeAdded by the GEMA TROJAN!
    Xdxdiag diagnosemsidxdia.exeAdded by a variant of the RBOT WORM!
    Xdxdiags.exedxdiags.exeAdded by the CERTIF-G TROJAN!
    XDxDialogdxdlg32.exeAdded by the VB-CXT TROJAN!
    Xdxdll32ntxdll.exeAdded by the GAOBOT.CPX WORM!
    NDXDllRegExedxdllreg.exeCreated when you select "Yes" to check the "WHQL Digital signatures" in the DirectX9 files at the first time you open it
    XDxLoadDX3DRndr.exeAdded by the GIBE.B WORM!
    NDXM6Patch_981116p_981116.exeWin32 cabinet self extractor. More info here
    Xdxmsrvdxmsrv.exeAdded by an unidentified WORM or TROJAN!
    XDxstyDxsty.exeAdded by the GEMA TROJAN!
    XDxupdate.exeDxupdate.exeAdded by the MAFEG WORM!
    Xdxviddxvid.exeAdded by Trojan-Downloader.Win32.Dluca.by TROJAN!
    XDyFuCAoptimize.exeAdult content dialler - see here
    XDyFuCA Active Alertactalert.exeAdult content dialler - see here
    XDynamic DHCPdydhcp.exeAdded by the RINBOT.B TROJAN!
    XDynamic Dns Binarydynitora.exeAdded by the RBOT-WT WORM!
    XDynamic Dns BinaryCMD16.EXEAdded by the RBOT-XM WORM!
    XDynamic Dns Binarywinxp34.exeAdded by a variant of the RBOT WORM!
    XDynamic Dns BinaryWinHelpcfn.exeAdded by a variant of the RBOT WORM!
    XDynamic Link Library loaderLoader32.exeAdded by the KOL TROJAN!
    UDynDNS UpdaterDynDNS.exeDynamic DNS IP address updater tool, used as a client for Dynamic DNS service providers such as http://www.DynDNS.org
    NDynDNS-Updater Traytoolddutray.exeDynDNS updater tray icon - allows easy configuration of the Dynamic DNSSM service. Can be run manually
    XDynHttp Dns Binarydynizari.exeAdded by a variant of the RBOT WORM!
    UDynSiteDynSite.exeDynSite - dynamic DNS client, also called an automatic IP updater
    UDynu Basic Clientdynubas.exeDynu online dynamic IP update client. Useful when using a dial up modem
    ?DZKillMeDZSAVEME.EXE??
    UD_V_Tdvt.exeDICOM Validation Tool - "DICOM is increasingly being used as the standard communication mechanism when integrating various medical products in a hospital environment"
    ?D_V_Tdvt.exeInstallation could be a crack/hack to NOD32 here. Seen and removed in many logs. Investigate it further and if this file is present C:d_v_t.reg then it should be fixed. Not to be confused with the DICOM entry here. Both files are located in the Windows/Windir directory
    XE-Cardecard.exeAdded by the YODI WORM!
    UE-colorIconMgr.ExeSets the colour of your monitor when running games that recognise E-Color so that you get 'what the game designer intended' when you see the game. Also allows monitor callibration through a program called 3-Deep. If you play a lot of games it can be useful. Can be disabled from starting up from within the program
    XE-nrgyPlusE-nrgyPlus.exeAdded by the Energyplus TRACKWARE! Tracks internet activity including websites visited and queries made at popular search engines. This information along with some system information is sent to a remote site
    Xe-Surveiller Stationestation.exeESurveiller spyware. Note - ESurveiller is spyware that monitors and records keystrokes and mouse clicks, instant message conversations, Internet activity and applications used, must be manually installed
    UE06DXLRD_7604703EDICT.EXERelated to Microsoft Encarta dictionary functions
    NE6TaskPanelTaskPanl.exeEarthlink Task Panel - part of Earthlink TotalAccess 2003 internet access software. Quick access to internet, E-mail and web-space
    NEA CoreCore.exeElectronic Arts EA Link software - "gives you a secure yet simple way to download EA PC games and patches, as well as other exclusive content"
    Ueabconfg.cplEabServr.exeEasy Access Buttons control panel on Compaq laptops. Only required if you use the extra keys
    XEac Downloaddownload.exeWebcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Now no longer available and supported and when available was classed as spyware - see here
    UEACLEANeaclean.exeFor Compaq PC's. Easy Access button support for the keyboard
    XEac_Cnrycanary.exeAdded by the CANARY TROJAN!
    ?Eac_rnvdlANTIVIRUS_INSTALL.EXE??
    UEanthologyAppEANTHO~1.EXEeAcceleration Stop-Sign security software related. Previously not recommended, see here
    UEanthologyAppeanthology.exeeAcceleration Stop-Sign security software related. Previously not recommended, see here
    Ueanthology_install.exeeanthology_install.exeeAcceleration Stop-Sign security software related. Previously not recommended, see here
    Ueanth_critical_update_alertsys_alert.exeeAcceleration Stop-Sign security software related. Previously not recommended, see here
    Ueanth_system_patchersys_alert.exeeAcceleration Stop-Sign security software related. Previously not recommended, see here
    NEapcisetupsbsetup.exeRockwell RipTide soundcard application software. Sound works without it
    NEAPCISETUPwizard.exePart of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation
    YEarthlink Protection Control Centerelnk_pcc.exeEarthLink Protection Control Center - "powerful, integrated security program makes it easier than ever to protect yourself against viruses, spyware, and hackers-all from one convenient location"
    NEarthLink ToolBar 5.0etoolbar.exeEarthLink Toolbar is a tool to help you get to all of the resources of the internet. EarthLink 5.0 Setup adds a few basic buttons to the Toolbar, but you can delete these or add more buttons any time
    UEasy Keyeasykey.exeFor programming of the built-in functions keys on some laptops (and maybe desktops). Required if these are used
    NEasy Start Buttonesb.exeProvides functionality on certain laptops that have additional keys. Not required unless you use the extra keys
    UEasy-PrintToolBoxBJPSMAIN.EXEA utility to launch the applications that are bundled with a Canon bubblejet printer
    XEasyAVEasyAV.exeAdded by the NETSKY.S or NETSKY.T WORMS!
    XEasyDatesEasyDates.exePremium rate adult content dialler
    XEasyDates_gbEasyDates_gb.exe"Edate-A" premium rate adult content dialler
    XEasyDates_nlEasyDates_nl.exeAdult content dialler
    UEasyKeyeasykey.exeFor programming of the built-in functions keys on some laptops (and maybe desktops). Required if these are used
    UEasyKeyboardLoggerEasyKeyboardLogger.exeEasyKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!
    UEasyLinkAdvisorLinksysAgent.exeLinksys EasyLink Advisor - "the free application that provides and easy way to setup, view, manage, and repair your network"
    UEasyMessageem2.exeEasy Messenger, instant messenger for MSN, AOL, ICQ, and Yahoo. See here
    XEasySearchBarESBUpdate.exeEasySearchBar adware downloader
    XeasyServServer.exeAdded by the EASYSERV TROJAN!
    XEasySpywareCleanerEasySpywareCleaner.exeEasySpywareCleaner spyware remover - not recommended, see here
    UEasySync ProXCPCMenu.exeEasySync Pro is a Lotus (now owned by IBM) program for synchronizing a PDA with Lotus Notes
    UEasyTuneIIIEasyTune.exeTuning (overclocking) utility for Gigabyte motherboards. Shortcut available
    UEasyTuneIVET4Tray.exeTuning (overclocking) utility for Gigabyte motherboards. Shortcut available
    UEasyTuneVGUI.exeTuning (overclocking) utility for Gigabyte motherboards. Shortcut available
    Xeasywwweasywww2.exeAdded by an unidentified VIRUS, WORM or TROJAN!
    UeAudioeAudio.exeAcer eAudio Management provides centralized control over notebook audio, and specialized audio modes for movies, music and games
    XEbatesMoeMoneyMakerwjview ...CodeEbates adware
    XEbatesMoeMoneyMaker0EbatesMoeMoneyMaker0.exeEbates adware
    XeBay ToolbarEBAYTBAR.EXEeBay Toolbar - reportes as spyware as it "phones home"
    UeBayToolbareBayTBDaemon.exeeBay toolabar related - also contains eBay account Guard which monitors for fraudulent eBay sites
    Xebmmmebatesmmmv.exeEbates adware
    UeBoardEboard.exeeMachines multimedia keyboard manager. Required if you use the extra keys
    NeBotDownloadWizard.exeeBot from Digital River - "helps ensure your computer always has the latest technology, fixes, add-ons, upgrades and 'cool stuff'." Can optionally be installed with software such as Net Nanny internet filtering software. Available via Start -> Programs
    UEC21EZQ.EXERelated to EC21. "EC21 is the world?s largest B2B marketplace to facilitate online trades between exporters and importers from all around the world"
    UECentergtb.exeDell E-Center/Google Toolbar related
    NECenterEULALauncher.exeEnd User License Agreement (EULA) launcher - related to Dell E-Center/Google Toolbar
    Xeckoclaro.exeAdded by the DLOADR-AQJ TROJAN!
    ?ecpeECPE.EXE??
    UeDataSecurity LoadereDSloader.exePart of Acer Empowering Technology. "Acer eDataSecurity Management is a handy file encryption utility that protects files from being accessed by unauthorized persons, using passwords and advanced encryption algorithms"
    Nedexteredexter.exeeDexter supplements internet filtering by substituting local images for filtered images in order to prevent browser stalls and other annoyances. Can be activated manually when starting the browser
    Xeditpadeditpad.exeAdded by the CONSPER-B TROJAN!
    NEDLoaderDTLoader.exeEffective Desktop from MiniStars Software - desktop management software no longer being supported
    UeDonkey2000edonkey2000.exeFile sharing network - not recommended as the free version of this application should be avoided as it installs, without permission, New.Net, Webhancer, WebSearch Toolbar and WinTools
    UEDRestore??Set Point from Easy Desk Software - "small utility that automatically sets System Restore points for WinME/XP"
    Xeducational writer[random filename]Added by the RBOT-LZ WORM!
    UEdwizardEdwizard.exeSafeGuard Easy - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks"
    XEDxMC110Isass.exeAdded by the VB-NIA WORM!
    XEdzy AntiVirusdppsfa.exeAdded by a variant of the RBOT WORM!
    NEEventManagerEEventManager.exePart of the Epson Creativity Suite supplied with their multi-function printer/scanners, Event Manager launches File Manager or PageManager for EPSON automatically when you press the B&W Start or Color Start button on the control panel in Scan mode
    XEfata[random 5 characters].exeAdded by the FLUKAN-D WORM!
    UeFax 4.2J2GDllCmd.exeeFax Messenger fax software
    UeFax DllCmdJ2GDllCmd.exeeFax Messenger fax software
    NeFax Tray MenuHotTray.exeeFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here
    UeFax Tray MenuJ2GTray.exeeFax Messenger fax software tray menu
    NeFax.com Tray MenuHotTray.exeeFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here
    Xefaxs lptt01efaxs.exeRapidBlaster variant (in a "efaxs" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
    Xefaxs ml097eefaxs.exeRapidBlaster variant (in a "efaxs" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
    UEFI Hot Foldershffw.exe"EFI Hot Folders improves productivity by simplifying the printing of PostScript and PDF files into a select, drag, and drop process. Once users create Hot Folders with different printing and finishing parameters, files are printed without opening an application or print driver menu." Part of EFI's high-end printing solutions
    UEFI Job Monitor[path] efjm.dll,runRicoh Imagio Printer/Scanner driver status monitor
    UEfpap.exeEfpap.exeEasy File & Folder Protector. Deny access to certain files and folders, or to hide them securely from viewing and searching
    Ueguiegui.exeUser interface for ESET NOD32 Antivirus and Smart Security
    XehSchedehSched.exeAdded by the SDBOT-DHF WORM!
    UehTrayehtray.exeMicrosoft Media Center Tray Icon gives easy access to the digital media manager for Windows Vista Home Premium and Media Center Edition
    Xei10.exeei10.exeAdded http://www.sophos.com/security/analyses/viruses-and-spyware/w32agobotnk.html" target=_blank>AGOBOT-NK WORM!
    UEicon NetworksLAN_DAEMONwatch.exeAssociated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually
    UEicon TechnologyLAN_DAEMONwatch.exeAssociated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually
    Xeixfichina.batAdded by the WCUP.A WORM!
    UElbycheckElbyCheck.exeFrom Elaborate Bytes who make CloneCD - monitors the installed filters of CD-ROMs/DVD-ROMs. Note - under Win2K removing this from startup causes the CD drive in the computer to not be recognized in the OS and after rechecking it prompts that the driver has been corrupted and asks you to restart the computer to fix it
    UElectron MicroscopeEMIII.exeElectron Microscope or EM - is a program used to track Stanford's distributed computing program client called Folding at Home, FAH. It will monitor up to 50 clients and give you the details about each client's progress as the FAH client runs. EM will also show you what each change in the protein looks like as the process continues
    XElementElement.txtAdded by the ELEM TROJAN!
    Xelement furth[path] repcale.exe [path] palsp.exeAdded by a variant of the RANDON.AN WORM!
    Xelitemediaelitemediapop.exeAdded by the LOWZONE-BB TROJAN! Also known as Elitebar/EliteToolbar/EliteSidebar adware
    NelmElmenv.exeViaTech eLicense for securing, distributing and selling music online
    XELNKProxysmproxy.exeSurfmonkey adware
    UELSA WINman SuiteWinmsuit.exeAllows you to totally customize your ELSA graphics card settings, including overclocking the GPU
    YElsaCapiCtlRcapi.exeAssumed to stand for Remote Common Application Programming Interface (RCAPI), this was installed with an Elsa Microlink ISDN modem. If it is not there you can not bring up the dialog box which is sometimes needed to reset the modem
    UELSAChipGuardelsavect.exeChipGuard for ELSA graphics cards - monitoring solution which monitors both the GPU temperature and fan speed, and will halt the system if either are at dangerous levels and restore the default clock speeds upon reboot. Leave enabled if overclocking
    UELSBLaunchELSBLaunch.exeEarthLink SpamBlocker
    NEMA.exeEMA.EXETime management system which helps you to manage your time and appointments
    UeMachines eBoardEboard.exeeMachines multimedia keyboard manager. Required if you use the extra keys
    YEmail Protectionemlproxy.exeAntiVirus Quick Heal - E-mail protection
    YEmailScanmcvsescn.exeRelated to McAfee AntiVirus suite - used to automatically scan incoming e-mails
    XeMakeSVEMAKESV.EXE"Switch" adult content dialer
    XeMakeSVEMAKE2B.EXE"Switch" adult content dialer
    UEMBASSY Trust Suite Secure UpdateAutoUpdate.exeUpdates for Wave Systems Corp. Embassy Trust Suite - "delivers advanced levels of security to the client PC using the TPM security chip found on most enterprise PCs today"
    XeMCryT Sh3ars Panagers[path to worm]Added by the RBOT-AWI WORM!
    UEMMeterEMMeter.exe"Express Meter provides detailed information about how your software assets are being used. With Express Meter you can monitor application usage, identify software usage patterns, and control application launches?all of which can help you make better decisions about your IT investments"
    Xemoc0reemo.exeAdded by the AGOBOT-AGE WORM!
    Uemozeemoze.exeemoze pcConnector - "Push your personal & business emails, contacts & calendar directly to your mobile device!"
    Xempine121307.exeDelfin Media Viewer adware related
    Xempine121307.Stub.exeDelfin Media Viewer adware related
    UEmpowering Technology LaunchereAPLauncher.exeEmpowering Technology Launcher, installed on Acer computer
    Xemsw.exeemsw.exeAttune HelpExpress - spyware. Disable and uninstall - see here
    Xemuleemule.exeAdded by the RBOT-ALZ WORM!
    NeMuleemule.exeeMule peer-to-peer file sharing client. Located in an eMule subdirectory of the Program Files directory
    NeMusicClient SystrayeMusicClient.exeeMusic MP3 download software
    UEM_EXECEM_EXEC.EXELogitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as "SmartMove". If you disable it and find you don't need it leave it disabled
    NEN4060C Taskbaren4060ct.exeComes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
    XenBrowser[name of file]WINBO adware
    ?encapsulated command toolwintr.com??
    NEncarta Dictionary QuickshelfQSHLFED.EXEProvides quick access to Encarta's Dictionary features?
    NENCMONITORmonitor.exeThe Encompass Monitor. This program is the Connect Direct Program.  It is more trouble than it is worth and few use it
    NEncoder AgentWMENCAGT.EXEMS Windows Media Encoder, which already has a shortcut in the Start Menu if installed
    UEncompass_ENCMONTRENCMONTR.EXEOptional simple browser from Yahoo (Encompass)
    ?ENCSurfsurfboard.exe??
    NEnergizer FileSaverEnergizer FileSaver.exeEnergizer FileSaver - UPS back-up utility for Energizer UPS products. From their Tech Support staff this is known to have a memory leak since it's release - with no fix planned! It will grab 2-5 handles per second and crash the average system in less than 3 days - therefore not recommended
    XEnergyPlugInEnergyPlugin.exeEnergyPlugin adware variant
    Uenginecs2enginecs2.exeCyber Sentinel - internet filtering software
    YEngUtilEngUtil.exePart of Roxio EasyCD Creator 6.0 - corrects any modification made to the Roxio Engine, it exits after checking
    XEnh Win Updtenhupdt.exeAdware - detected by Kaspersky as the ONECLICKNETSEARCH.H TROJAN!
    Xenhance32enhance32.exeAdded by the CRYPTER.A TROJAN!
    NEnigmaPopupStopEnigmaPopupStop.exePart of Enigma SpyHunter - not recommended, see note
    ?ENSApServer2_0APSERVER.EXEIntel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?
    ?ENSMIX32.EXEENSMIX32.EXESound card driver. Is it required?
    UEnsoniqMixerstarter.exePuts the Ensoniq mixer in system tray. From Ensoniq Technologies "Our mixer is a critical part of the soundcard as it fixes sound problems and replaces the MS mixer which can no longer be used". If you find you don't need it - try one of the solutions on this special page. Similar to Creative PCI Audio Configuration Utility
    UEntbloess 2Entbloess2.exeRelated to Window-Switcher (now Reflex Vision) - it allows you to see previews of all your open applications via a single keystroke in a manner similar to Apple's Expos?, for Windows 2K/XP
    UEnterra Icon KeeperIcnKeepr.exeIcon Keeper - "tool to save and restore icon positions on the desktop"
    XEnumerate Servicewsys.exeAdded by the MANIFEST TROJAN!
    YEnvyHFCPLEnMixCPL.exeVIA Envy24 PCI Audio Controller driver
    UeonemngeOneMng.exeeOne Manager, provides access to the buttons on the keyboard and on the front of the console for the eMachines eOne PC
    UEOUAppEOUWiz.exeIntel ProSET Wireless related - provides additional configuration options for these devices
    UEOUWizEOUWiz.exeIntel ProSET Wireless related - provides additional configuration options for these devices
    UEPM-DMepm-dm.exeDevice Manager - part of Acer Empowering Technology. "Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles, or to create their own customized profiles"
    UePowerManagementePM.exePart of Acer Empowering Technology. "Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles, or to create their own customized profiles"
    UePower_DMCePower_DMC.exePart of Acer Empowering Technology. "Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles, or to create their own customized profiles"
    UEPoXUSDMUSDM.EXEEPoX Universal Serial Data Monitor - a diagnostics tool that shows Temps, Fan Speeds, Voltages...etc
    NePrint 3.0 ServiceEPRINT3.EXELEADTOOLS ePrint file conversion software - "convert any file to and from over 150 document and image formats including searchable PDF, DOC, HTML, TXT, Multi-page TIFF, JPG, GIF, PNG and many more!" Can be started manually
    NePrint 4.0 ServiceEPRINT4.EXEA component of the "LEADTOOLS ePrint File Conversion Software - Convert ANY file to and from over 150 document and image formats including searchable PDF, DOC, HTML, TXT , Multi-page TIFF, JPG, GIF, PNG and many more!" Can be started manually
    UePrompterePrompter.exeePrompter - E-mail notification software
    NEPSe_srcv02.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
    NEPSe_srcv03.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
    NEPSON Background MonitorSTMS.EXESupposed to keep an Epson printer ready for quick printing.  Users report little difference whether it is on or not
    UEPSON CardMonitorEPSON CardMonitor1.0.exeMonitors the PCMCIA memory card slot on EPSON cameras and printers and launches PhotoStarter or PhotoPrint
    NEPSON Status Monitor 3 Environment Checke_srcv03.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
    NEPSON Status Monitor 3 Environment Checke_srcv02.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
    NEPSON Status Monitor 3 Environment Check 2e_srcv03.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
    NEPSON Status Monitor 3 Environment Check 2e_srcv02.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
    UEPSON Stylus C40 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C40 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus C41 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C41 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus C42 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C42 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus C43 SeriesE_S08IC1.EXEEpson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus C43 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus C44 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C44 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus C45 SeriesE_S4I3T1.EXEEpson Status Monitor 3 for the Stylus C45 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus C46 SeriesE_S4I0T1.EXEEpson Status Monitor 3 for the Stylus C46 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus C60 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus C61 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C61 Series printer - for monitoring printer status, checking ink levels, etc
    UEpson Stylus C62 SeriesE-S0BIC1.EXEEpson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus C62 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus C63 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C63 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus C64 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus C66 SeriesE_S4I0S2.EXEEpson Status Monitor 3 for the Stylus C66 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus C67 SeriesE_FATIAAL.EXEEpson Status Monitor 3 for the Stylus C67 Series printer - for monitoring printer status, checking ink levels, etc
    UEpson Stylus C82 SeriesE_S0HIC1.EXEEpson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus C82 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus C84 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus C84 SeriesE_S4I2D1.EXEEpson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus C87 SeriesE_FATIABL.EXEEpson Status Monitor 3 for the Stylus C87 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus CX2900 SeriesE_FATIBFP.EXEEpson Status Monitor 3 for the Stylus CX2900 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus CX3200E_S10IC2.EXEEpson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus CX3600 SeriesE_FATI9BE.EXEEpson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus CX3800 SeriesE_FATIACA.EXEEpson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus CX4200 SeriesE_FATIAEA.EXEEpson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus CX4500 SeriesE_FATI9AP.EXEEpson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus CX5400E_S4I2G1.EXEEpson Status Monitor 3 for the Stylus CX5400 printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus CX6000 SeriesE_FATIBIA.EXEEpson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus CX6500 SeriesE_FATI9EP.EXEEpson Stylus CX6500 Series printer monitor - for checking ink levels, etc
    UEPSON Stylus CX6600 SeriesE_FATI9EE.EXEEpson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus CX7000F SeriesE_FATIBKA.EXEEpson Status Monitor 3 for the Stylus CX7000F Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus CX7800 SeriesE_FATIAFA.EXEEpson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus CX8400 SeriesE_FATICEA.EXEEpson Status Monitor 3 for the Stylus CX8400 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus D68 SeriesE_FATIAAE.EXEEpson Status Monitor 3 for the Stylus D68 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus D78 SeriesE_FATIBGE.EXEEpson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus D88 SeriesE_FATIABE.EXEEpson Status Monitor 3 for the Stylus D88 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus DX3800 SeriesE_FATIACE.EXEEpson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus DX4000 SeriesE_FATIBEE.EXEEpson Status Monitor 3 for the Stylus DX4000 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus DX4400 SeriesE_FATICAE.EXEEpson Status Monitor 3 for the Stylus DX4400 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus DX4800 SeriesE_FATIADE.EXEEpson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus DX5000 SeriesE_FATIBVE.EXEEpson Status Monitor 3 for the Stylus DX5000 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus DX6000 SeriesE_FATIBIE.EXEEpson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus DX8400 SeriesE_FATICEE.EXEEpson Status Monitor 3 for the Stylus DX8400 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus Photo 2200E_S10IC2.EXEEpson Status Monitor 3 for the Stylus Photo 2200 printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus Photo 825E_S10IC2.EXEEpson Status Monitor 3 for the Stylus Photo 825 printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus Photo 925E_S10IC2.EXEEpson Status Monitor 3 for the Stylus Photo 925 printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus Photo R1800E_FATI9LA.EXEEpson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status, checking ink levels, etc, etc
    UEPSON Stylus Photo R200 SeriesE_S4I0H2.EXEEpson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus Photo R220 SeriesE_S6I2I1.EXEEpson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus Photo R220 SeriesE_FATIAIE.EXEEpson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus Photo R240 SeriesE_FATIAHE.EXEEpson Status Monitor 3 for the Stylus Photo R240 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus Photo R260 SeriesE_FATIBNA.EXEEpson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus Photo R300 SeriesE_S4I2F1.EXEEpson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus Photo R300 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus Photo R320 SeriesE_FATI9FA.EXEEpson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus Photo R380 SeriesE_FATIBOA.EXEEpson Status Monitor 3 for the Stylus Photo R380 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus Photo RX420 SeriesE_FATI9CE.EXEEpson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus Photo RX430 SeriesE_FATI9CP.EXEEpson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus Photo RX500E_S4I2K1.EXEEpson Status Monitor 3 for the Stylus Photo RX500 Series printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus Photo RX600E_S4I2M1.EXEEpson Status Monitor 3 for the Stylus Photo RX600 printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus Pro 4000E_S10IC2.EXEEpson Status Monitor 3 for the Stylus Pro 4000 printer - for monitoring printer status, checking ink levels, etc
    UEPSON Stylus Pro 7600E_S10IC2.EXEEpson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status, checking ink levels, etc
    UEpsonPhotoStarterEPSON_PhotoStarter.exeOnly needed if you want to make full use of the capabilities of an Epson printer that included this 
    XEptrnopdb.exeAdded by an unidentified WORM or TROJAN!
    XEQAdviceEQAdvice.exeNewAds1 adware
    UEQArticleEQArticle.exeEQArticle adware
    ?EquipmenEquipmen.exe??
    UErasereraser.exeEraser allows for complete removal of data from your hard drive
    UeRecoveryServicecheck.exeAcer Notebook related. Acer eRecovery allows the user to restore the operating system or backup the current system profile, thus ensuring system integrity
    UeRecoveryServiceMonitor.exePart of Acer Empowering Technology. "Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer, and also acts as a versatile standalone backup and recovery manager"
    UeRecoveryServiceeRAgent.exeAcer's eRecovery Management program. This program allows you to create and restore backups of your computer
    NERegreg32.exeEReg is a software registration tool incorporated on products such as those by Br?derbund, Connectix, Hewlett-Packard, The Learning Company, and Sierra. Needless to say you don't need it
    Xerfgddfkwind2ll2.exeAdded by the BEAGLE.CQ WORM!
    Xerghgjhgdrwindlhhl.exeAdded by the BEAGLE.BG WORM!
    Xerghgjhjgdrwindlhhl.exeAdded by the BEAGLE.BG or BEAGLE.BH or BEAGLE.BI or BEAGLE.BJ WORMS!
    ?ermerm.exe??
    Xeros.exeeros.exeAdult content dailler
    XErrCleanSysRep.exe ErrClean misleading security software - not recommended, see here
    NError NukerErrorNuker.exeErrorNuker registry cleaner - only required if you want the application to run a scan at startup. The program can be launched manually if required
    XError Safeers.exeErrorSafe misleading security software - not recommended, see here
    XErrorGuardErrorGuard.exeSpyware remover - not recommended, see here
    Xerrorhandlererrorhandler.exeErrorHandler adware
    XERSers_startupmon.exeErrorSafe misleading security software - not recommended, see here
    Xerscwerscw.exeErrorSafe misleading security software - not recommended, see here
    XERS_checkers_startupmon.exeErrorSafe misleading security software - not recommended, see here
    Xerthegdrwindll2.exeAdded by the BEAGLE.CG WORM!
    Xerthgdrwindll.exeAdded by the BEAGLE.AO or BEAGLE.AQ WORMS!
    Xerthgdrsvc.exeAdded by the BEAGLE.BN or BEAGLE.BP WORM!
    Xerthgdr2svc23.exeAdded by the BAGLE.CG WORM!
    ?ERTS0749ERTS0749.exeIBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?
    UERUNT AutoBackupAUTOBACK.EXEERUNT backup utility - when added to the user's startup folder automatically backs up the registry each time the system boots, resulting in numerous backups that can be restored
    Xerwghjjrjtucbcg.exeAdded by the SMALL.CUL TROJAN!
    YeSafe ProtectESPWatch.exeeSafe from Aladdin - internet security for gateway and E-mail servers
    UESBesb.exeEasy Start Button - provides functionality on certain laptops that have additional keys. Not required unless you use the extra keys
    YeScan MonitorAVKWCTL9X.EXEMicroWorld eScan antivirus
    UeScan Scheduleravkserv.exeMicroWorld eScan antivirus scheduler
    UeScan UpdaterTrayicos.exeMicroWorld eScan antivirus updater - allows users to automatically download updates and set the auto time interval for downloads
    XEScorcherescorcher.exePart of eScorcher anti-virus software - responsible for performing virus checks and deletions. Used to collect information about the user and therefore treated as spyware - now the web-site is dead
    NESFTPesftp.exeESftp - FTP client for transfering files between a local PC and another remote computer
    UeSnipsClientGW.exeeSnips Client Gateway from eSnips
    XEsohEsoh123.exeAdded by the AGOBOT.FF WORM!
    XEspecialDeneca.batAdded by the DELUZ VIRUS!
    NESPN BottomLinebline.exeESPN BottomLine. "You can dock the BottomLine to the top or bottom of your screen or drag it around on your desktop, without even worrying about a browser. As long you keep the BottomLine running, you will continue to receive live scores and breaking news, and by clicking on any score or news item, you will be taken directly to the corresponding page on ESPN.com for a full break down."
    ?ESS DaemonEssd.exeRelated to an ESS based soundacard. Is it required?
    ?essapmessapm.exeESS Solo soundcard driver. Is it required?
    YEssdcessdc.exeRelated to an ESS Solo soundcard. Seems as though it's required
    ?ESSNDSYSESSNDSYS.EXERelated to an ESS based soundacard. Is it required?
    YESSOLOESSOLO.exeSound card driver that re-instates itself every time it's removed
    Yesspkesspk.exeESS Technology modem speaker driver file. Required to get on-line with this modem
    UEssSpkPhoneessspk.exeESS Technologies Call waiting, which gets installed by the drivers for V92 modems based on ESS Technologies chipsets
    ?eSupIniteSupCmd.exeRelated to SupportSoft (aka Support.com) "Real-Time Service Management software". What does it do and is it required?
    XETB Testeretbtest.exeAdded by the RBOT-ABR WORM!
    Xetbrunelit***32.exe [* = random char]EliteBar adware
    UeTCertMangereTCrtMng.exeeToken Certificate Manager from Aladdin Knowledge Systems, Inc. A USB-based authentication, providing strong user authentication and password management solutions
    NEthernettcaudiag.exe3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs
    Xethernetairftp.exeAdded by a variant of the SDBOT WORM!
    Xethernetmsnger.exeAdded by a variant of the SDBOT WORM!
    Xethernetmsftp.exeAdded by the SDBOT.BXJ WORM!
    Xethernet adaptercsrmss.exeAdded by a variant of the RBOT WORM!
    XEthernet Drivercmsrrs.exeAdded by a variant of the RBOT WORM!
    XEthernet Driverssmrrs.exeAdded by the RBOT-AAK WORM!
    XEthernet Driversethernet.exeAdded by the GAOBOT.CEZ WORM!
    XEthernet Linkingethernet.exeAdded by a variant of the IRCBOT TROJAN!
    XEtrafficJavaRun.exeTopMoxie adware
    YeTrust EZ Firewallefpeadm.exeeTrust EZ Firewall
    UeTrust PestPatrol Active ProtectionPPActiveDetection.exePestPatrol real-time protection feature. "Stops spyware before it infects your system"
    XeTrust Realtime Monitorrealmon.exeAdded by the LAZAR.B TROJAN!
    YeTrustCIPEezdsmain.exeeTrust EZ Deskshield from Computer Associates. Protects against malicious email attachments and unauthorized use of email by detecting and blocking unusual behavior
    XeTunnelwinfw.exeAdded by an unidentified TROJAN!
    UEudoraEudora.exeEudora from Qualcomm allows you to receive and send Internet e-mails
    XEUP Serviceeupsvc.exeAdded by the DELBOT-Q WORM!
    UEuroGlotEuroGlot.exeEuroglot - "multilanguage translating system, available in the languages Dutch, English, French, German, Spanish and Italian"
    ?Event Logeventlog.exe??
    NEvent Planner RemindersPLNRnote.exeSierra Event Planner tray icon
    NEvent Reminderpmremind.exeA calendar/alarm program that installs with Br?derbund Printmaster
    XEventApplicationCmdsmschk.exeAdded by the IRCBOT-AO TROJAN!
    UEVENTLISTENEREvLstnr.exeUsed with a Nikon digital camera to recognize when the camera is plugged in
    Neventmgreventmgr.exeUsed with a Microtek scanner. Manages the scanner's button events. Available via Start -> Programs
    Xeventwvreventwvr.exeAdded by the COSIAM_G TROJAN!
    ?EverioServiceEverioService.exeRelated to the Cyberlink software supplied with JVC's Everio camcorders. What does it do and is it required?
    UEvidence Cleanerecleaner.exeEvidence Cleaner cleans up tracks left by your PC and Internet activities
    NEvidence Eliminatoree.exeEvidence Eliminator - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basis
    XEvilEvil.exeAdded by the MYTOB.JM WORM!
    Nevntsvcevntsc.exeApplication Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable "tkbell.exe" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK
    UEVOLOSTAEVOLOSTA.EXEEvolo Status Monitor for wireless network cards. Allows a user to enter a specific access-point mode SSID, peer-to-peer mode channel, link speed, WEP encryption options, and has enable/disable and rescan buttons. It is not needed if using Windows XP or higher, as they have this built-in to the control panel. Also, if the user is very sure that there is ONLY ONE network available to connect to, then they can remove this. If it is not in startup, and the user needs to run it, they can simply type EVOLOSTA in the Start -> Run dialog to run it
    UEvoluent Mouse ManagerEvoMouExec.exeMouse manager for Evoluent VertcialMouse
    XEvtHtmevthtm.exePremium rate adult content dialler
    UEW Message Servermsg32.exeConexant (older versions are Brooktree) Wavestream Message Server - associated with Conexant based audio devices
    NeWare StartupiWareStart.exeeWare iWare task bar. Not required
    Xewupdaterewupdater.exeEasyWebSearch adware updater
    Xexample[random filename].exeAdded by the NUCLEAR TROJAN! Note - this trojan file is found in the WindowsNR or WinntNR folder
    NExcite PlatformExlaunch.exeLoads an Icon in the startup tray that allows you to receive service update notices for Excite@Home if you desire (note that since Excite@Home appears to be winding down this becomes irrelevant). May also allow you to kill the Excite Toolbar that automatically loads in Internet Explorer
    ?Excite Private Messenger Pipex8impipe.exe??
    NExciteAssistantEXEASSISTANT.EXEWith Excite Assistant, you can access a wide variety of online information, including email, news, and stock quotes without having to have a browser window open
    Xexdl.exeexdl.exeBargainBuddy foistware
    Xexe lptt01exe.exeRapidBlaster variant (in a "Exe" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
    Xexe ml097eexe.exeRapidBlaster variant (in a "Exe" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
    Xexecfg4execfg4.exeAdded by the ELECTRON WORM!
    XExecUserExecUser.exeAdded by a variant of the RBOT WORM!
    ?Executedelfolders.exe??
    XExeName32Warm.scrAdded by the SCOLD WORM!
    XExFilterRundll32.exe [path] cdnspie.dll, ExecFilterCNNIC Update pest
    ?exgiwslexgiwsl.exe??
    UExif LauncherExiflaquickdcr.exeUSB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
    UExif LauncherQuickDCF.exeUSB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
    UExitKillerEkiller.exeExit Killer - automatically closes pop-up windows in your browser
    ?exmonhpimoniter.exeSome kind of hp digital camera maybe or a photo smart connection probe?
    XExnexn.exeAdded by the IRCBOT.RJ WORM!
    Xexpcrt[random filename]Added by a variant of the SLAPER TROJAN!
    XExpertAntivirusExpertAntivirus.EXEExpertAntiVirus misleading antivirus program - not recommended, see here
    XEXPL0RE.EXEEXPL0RE.EXEAdded by the POPNO-A TROJAN! Note that the filename is spelled using the digit "0" instead of the uppercase letter "o"
    XExpl0rer softexpl0rer.pifAdded by the RBOT-AQR WORM!
    XexplerUpdadv.exeAdded by the QQPASS-N TROJAN!
    XExplkwexpup.exeKeywords hijacker
    Xexplord.exeexplord.exeAdded by the DLOADR-AYW TROJAN!
    Xexploreexplore.exeAdded by any number of VIRUSES, WORMS or TROJANS!
    XExploreExplorer.exeAdded by the IRC.FLOOD.G TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually!
    XExploreexplore.exeAdult content dialler
    Xexplore managerexplore.exeAdded by the DONBOMB.A TROJAN!
    Xexplore.exeExplore.exeAdded by the GRAYBIRD.G TROJAN!
    Xexploreff.exeexploreff.exeAdded by the FINFANSE TROJAN!
    Uexplorerexplorer.exeStarts Windows Explorer. Unless this has been manually added to startups or added by another program it could be a virus such as PE_BISTRO or DVLDR or MYDOOM.C. Note that it is also not the explorer.exe task/service you'll see when via CTRL+ALT+DEL
    Xexplorerwscript.exe [filename]Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted
    XExplorershellexpl.exeAdded by the SHELDOR TROJAN!
    Xexplorerexpl32.exeAdded by the RATSOU TROJAN!
    XExplorer[path to worm]Added by the AUTEX WORM!
    XExplorershellexp.exeAdded by a variant of the SHELDOR TROJAN!
    XEXPLOREREXPL0RER.EXEAdded by the BEASTDO-Y TROJAN! Note the "0" in the filename rather than upper case "o"
    XEXPLORERsys.exeAdded by the SILLYFDC-A TROJAN!
    XExplorerconfig_.comAdded by the FLOPPY-D WORM!
    XExplorerdrv.exeAdded by the SMALL-FD TROJAN!
    Xexplorer[path to trojan]Added by the AGENT-EU TROJAN!
    Xexplorerexplorer.exeAdded by the KEYLOG-AK TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in a "service" subfolder of the System folder
    XEXPLOREREXPLORER.exeAdded by the NETHIEF-P TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in a "SHELLEXT" subfolder of the System folder
    Xexplorerexplorer.exeAdded by the BLOCKEY-A TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in a "config" subfolder of the System folder
    XexplorerYinstall.exePurityScan/Clickspring adware
    XExplorerWindows Explorer.exeAdded by the SILLYFDC-I WORM!
    XExplorerexplorar.vbsAdded by the DESKTO-A WORM!
    XExplorer Loaderexplr32.exeAdded by the AGOBOT.N WORM!
    XExplorer Loaderexplorerl.exeAdded by the SDBOT-ADI WORM!
    XExplorer lptt01explorer.exeRapidBlaster variant (in a "explorer" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!
    XEXPLORER MICROSOFT SYSTEMexplore.exeAdded by a variant of the RBOT WORM!
    XExplorer ml097eexplorer.exeRapidBlaster variant (in a "explorer" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!
    XExplorer softexplorer.pifAdded by the RBOT-APK WORM!
    XExplorer softexplorer.comAdded by the RBOT-ARM WORM!
    XExplorer UpdaterIEXPLORE.exeAdded by the SDBOT-WO WORM! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    Xexplorer.exeexplorer.exeAdded by the AGENT-EW or PWS-CY TROJANS! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    Xexplorer.exeexplorer.exeAdded by the DELF-ACL TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the Program Files folder
    XExplorer32Expl32.exeAdded by the HACKTACK.B TROJAN!
    XExplorer32explorer6s4.exeAdded by the Downloader.Win32.Small.biq TROJAN!
    XExplorer32efsdfgxg.exeAdded by the CLICKER-Y TROJAN!
    XExplorer6.1.EXEExplorer.exeAdded by the MYDOOM.B WORM!
    XExploreUpdSched[random filename]ZenoSearch adware
    XExploreUpdSchedncntnkwd.exeIdentified as a variant of the AdWare.Win32.ZenoSearch.am malware
    Xexporetwinset.exeAdded by the QQPASS-I TROJAN!
    UExpress ClickYesClickYes.exe"Express ClickYes is a handy tool that runs in the system tray automatically clicks the Yes button for the Outlook Security security prompt, that asks you to confirm mail sending from third party applications"
    UExshow95EXSHOW95.exeSupport software for some of the Kensington mice. Provides access to extra features like those available with enhanced Logitech and MS devices
    NExtender Resource MonitorRMSysTry.exeRelated to Windows Media Center from Microsoft
    XExternal DependenciesExternal.exeAdded by the MYTOB.EC WORM!
    UExtraDNSExtraDNS.exeExtraDNS - DNS configuration tool
    ?Extranet AutoDialAutoExt.exeNortel Networks Contivity Extranet Switching Software
    ?ExxtremeHelperDemonexxdemon.exeCreative Exxtreme graphics card related?
    NEye Tide Launcheroneeyetideone.exeNascar wallpaper
    XEYORENotepad.scrAdded by the GIMLET-A WORM!
    YEZ Firewallca.exeeTrust EZ Armor Internet Security
    Nezagentezagent.exeEzVCR recording software for the ASUS TV FM card. Available via Start -> Programs
    NEzButtonEzButton.EXEEZbutton is a quick launcher for the Media player app that comes with certain laptops
    NEZDeskEZDESK.EXEUtility that remembers icon locations for each user and resolution. Available here
    NEzEjMnApEzEjMnAp.exeFor IBM Thinkpad Notebooks. Quote: "The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once, rather than stopping each device individually". Available via Start -> Programs
    XeZmmodmmod.exeeZula TopText adware
    ?EZNORUNEZNORUN.EXEEasy Internet related?
    NEzPrintezprint.exeLexmark Fast Pics - helps users of their printers to enhance, print and manage their photos quickly and easily
    YezPS_PxezSP_PxEngine.exeEngine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings
    YezPS_PxezSP_Px.exeEngine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings
    YezShieldProtector for PxezSP_Px.exeEngine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings
    YezShieldProtector for PxezSP_PxEngine.exeEngine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings
    UEZSMART Appezsmart.exeEZ-S.M.A.R.T. hard drive monitoring software from StorageSoft - appears to be no longer supported
    XezulaeZmmod.exeeZula TopText adware
    XeZulaMaineZulaMain.exeeZula TopText adware
    XeZuluMaineZuluMain.exeComes with "KaZaA" installation. Advertising Spyware. Not required but KaZaA won't work
    XeZWOwo.exeeZula TopText adware
    UE_S10IC2E_S10IC2.EXEEpson Status Monitor 3 for the Stylus C44 Series printer - for monitoring printer status, checking ink levels, etc
    UE_S23E_SICN03.exeEpson printer status monitor - for checking ink levels, etc.
    UE_S4I2F1E_S4I2F1.EXEEpson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status, checking ink levels, etc
    NE_S4I2G1E_S4I2G1.EXEEpson Status Monitor 3 for the Stylus CX5400 printer - for monitoring printer status, checking ink levels, etc
    UE_SOEIC1E_SOEIC1.exeEpson Status Monitor 3 - for monitoring printer status, checking ink levels, etc
    UF-PROT Antivirus Tray applicationFProtTray.exeSystem Tray access to F-PROT Antivirus
    XF-Secure 2005svchost.exeAdded by the BIFROSE-CH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
    YF-Secure 2006fspex.exeF-Secure Anti-Virus automatic updater
    UF-Secure Management AgentFSMA32.EXEF-Secure antivirus - F-Secure Policy Manager provides tools for administering F-Secure software products
    YF-Secure ManagerFSM32.EXEF-Secure antivirus - carry out scheduled virus scans automatically
    YF-Secure Startup WizardFSSW.EXEF-Secure antivirus
    YF-Secure TNBTNBUtil.exeF-Secure antivirus
    YF-StopWF-StopW.exeF-Prot anti-virus background scanner by F-Risk Software
    Uf1Tray.exeF1TRAY.EXESystem Tray icon for FusionOne's MightyPhone software. "MightyPhone is a concept for wirelessly synchronizing the data on your mobile phone with your web-based or PC based organizer"
    ?f23mxinsf23mxinsRelated to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required?
    Xf607f607.exeAdded by the URAT.B TROJAN!
    Xf73cdc8ee94ebtsendto.exeAssociated with mysearchnow.com/searchbar.html
    Xf94mggfhfghodftdf[path to trojan]Added by the SMALL.JHZ TROJAN!
    UFamilyKeyLoggercisvc.exeFamily Keylogger is a program that lets you record to a special file and then view all the keystrokes typed by everyone using your computer. Keystroke logger/monitoring program - remove unless you installed it yourself!
    XFantasia injectorwincfg.exeAdded by the AGOBOT.US WORM!
    ?fapmonfapmon.exeFair Access Policy monitor for DirecPC/DirecWay internet access
    Xfarmmextfarmmext.exeVX2.Transponder parasite updater/installer related
    XFashFash.exeUnidentified adware
    Xfaslkakj11kjgagklj11.exeAdded by the LEGMIE-ARE TROJAN!
    Nfastfast.exeInstalls as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
    NFAST DefragFAST2.EXEFastDefrag defragmenting software
    XFast Homesvcnvt.exeDetected by Kaspersky as the DELF.KS TROJAN! This file may be found in the System folder on 9x machines, however as of this writing it has only been seen in the System32 folder
    XFast Searchsvcnv.exeHomepage, Startpage hijacker. Possible variant of Trojan-Downloader.Win32.Delf
    XFast startNtut.exeAdware - deteced by Kaspersky as the FAVADD.I TROJAN!
    XFast startsvcnt.exeAdware - detected by Kaspersky as a variant of the FAVADD TROJAN!
    UFastCachefc.exeFastCache from AnalogX - speeds up browsing by resolving DNS requests locally
    XFastStartntnut32.exeAdded by the STARTPAGE.L TROJAN!
    XFastStartsvcnut.exeBrowser hijacker - a variant of the STARTPAGE.L TROJAN!
    XFastStartsvcnut32.exeBrowser hijacker - a variant of the STARTPAGE.L TROJAN!
    NFastTrack AcceleratorSPEED UP.EXEFastTrack Accelerator - "speedup" utility for programs that use the FastTrack network such as KaZaA Media Desktop, Grokster and Morpheus
    XFASTTRACKNETVISIONNETVISION.exeDialCar-Z premium rate dialer
    UFastTVSyncFastTVSync.exePart of InterVideo DVD Copy 5 Platinum - "fast DVD copying and file conversion software. In just three steps, you can copy videos to most DVD formats, or convert them for smooth, flawless viewing on your PSP? or iPod?. With broad format support and unique CopyLater? technology, DVD Copy saves you time and ensures high-quality output like no other copying software"
    NFastUserfast.exeInstalls as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
    NFastUsrfast.exeInstalls as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
    UFatPipeDHCPSoftware enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
    UFatpipe Dialerfpdialer.exeDailler for Fatpipe - software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
    Ufatrecovfatrecov.exeSCKeyLog.j keystroke logger/monitoring program - remove unless you installed it yourself!
    UFavoriteSyncFavoriteSync.exeFavoriteSync keeps the same set of Internet Explorer Favorites on several computers in sync
    UFaxCenterServerfm3032.exeFaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark, MCI, Lotus, My Software, Broderbund, Traffic Software and many others
    UFaxCenterServer4_in_1fm3032.exeFaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark, MCI, Lotus, My Software, Broderbund, Traffic Software and many others
    UFaxCtrl.exeASMediaProxyServer.exePart of Avaya's Contact Center Express - "a multi-channel, high-volume software solution from Avaya designed specifically for the intelligent routing and computer telephony integration (CTI) needs of medium-sized contact centers"
    NFaxTalk CallControl 6.0FTClCtrl.EXEThis allows the software to handle incoming and outgoing communications without requiring the FaxTalk Communicator application to be loaded into memory. Can be started manually
    UFBDirectFBDirect.exeSoftware that monitors the status of a Visioneer OneTouch scanner button and allows you to scan, fax, copy, print, and easily communicate by simply dragging and dropping scans on your PaperPort Desktop!. The **** represents the model, 5300, 7600, etc. Available via Start -> Programs
    ?FBIFBISM.exeCompaq related but what does it do?
    Xfcrunfc.exeAdded by the CAMPURF WORM!
    XFCEngineFCEngine.exeCASClient adware
    XFCHelpFCHelp.exeAdded by either FCHelp adware or a variant of it
    XFCManFCMan.exeFCHelp adware
    XFdaemon securityfsecur.exeAdded by the SDBOT.KXO WORM!
    XFDD SYSTEMFdd.exeAdded by the MYTOB-FO WORM!
    XFdr Command Modulesp2.exeAdded by the SDBOT.WP WORM!
    XFDriverwindrv.exeAdded by the DELF.WG TROJAN!
    UFD_SAPFD.exeReported to be the autopassword program from the Sony Microvault thumb drive
    Ufeedreader.exefeedreader.exe"Feedreader is a freeware Windows application that reads and displays Internet newsfeeds aka ATOM and RSS feeds based on XML"
    Xfeelalrightmirc.exeAdded by the IRCFLOOD-M WORM!
    UFEELitDeviceManagerfeelitdm.exeAssociated with Immersion TouchSense devices (Logitech Wingman Force Feedback Mouse and possibly other peripherals)
    XfegozeSVCH0ST.EXEAdded by the GRAYBIRD.D VIRUS! Note - the filename has the digit 0 rather then the uppercase "o"
    UFellowes ProxyR3proxy.exeInstalled with Fellowes EasyPoint mouse software. Not necessary for normal functioning of Fellowes mice but it is necessary to use the extended features of all Fellowes mice
    XFen Startupsfensvc32.exeAdded by the RANDEX.CCF WORM!
    UFerrariWallPaperFerrariWP.exeCalendar that replaces the default desktop background image. It comes with every Acer Ferrari 3000 laptop. Also downloadable for members of www.ferrari.com
    Xffisffisearch.exeiSearch "Desktop Search" hijacker
    UFG1_00frntgate.exeFrontGate MX - e-mail spam blocker
    ?fgl23DoubleScreenHooksf23happ.exeRelated to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required?
    XfGQEGqHOMEgwwgtp.exeAdded by the RANKY.J TROJAN!
    XFHPageshdochp.exeAdded by the DELF-Ks TROJAN!
    XFHStartshdocsvc.exeAdded by the DELF-Ks TROJAN!
    UFhtisxkfhtisxk.exeXtraKeys keystroke logger/monitoring program - remove unless you installed it yourself!
    UFieldForms SyncSyncService.exeResco FieldForms. A solution for building of mobile forms that can be viewed or filled in on the run, on a wide range of mobile devices. Supports Microsoft Access databases, and provides for synchronization of other data as well
    XFiendlyTypecsrss.exeAdded by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
    XFILEabcdefg.exeAdded by the KELVIR.DD WORM!
    ?file indexing servicemsfindfile.exeNew version of MS FindFast and still a resource hog?
    Xfile laoder configurationrnd32.exeAdded by the RBOT.BQJ WORM!
    XFile Mapping Serviceshp-1003.exeAdded by the RBOT.FAN WORM!
    XFile Protection Monitorfilemon.exeAdded by a variant of the RBOT WORM!
    XFile Systemtaskmqrs.exeAdded by a variant of the TOXBOT/CODBOT WORM!
    XFile Systemtaskmqr.exeAdded by the RBOT.BWQ WORM!
    XFile System Servicewmiprvsc.exeAdded by the AGOBOT-HZ TROJAN!
    XFile0_0MD1.exeAdded by the DLOADER-OR TROJAN!
    XFile1Dia Claro.htmAdded by the DLOADER-OR TROJAN!
    XFileFreedom_Pluginwtm.exeFileFreedom peer-to-peer sharing program
    XFileManager32Wscript.exe ChkMgr32.vbsAdded by the NOTUP.A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "ChkMgr32.vbs" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    XFileSoftWscript.exe UpdataFiles.vbsAdded by the SST.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "UpdataFiles.vbs" file is located in the Winnt or Windows folder
    UFilmLoopFilmLoopService.exeRelated to FilmLoop - a photocasting network. Share your pictures with your family and friends
    UFilterGatefiltergate.exeFiltergate internet filtering software - filters sounds, popup ads, background sound and other unnecessary website items
    UFilterguardFiltrgrd.exeAn icon located in the lower left of the screen and looks like a lifesaver. This icon is a "short-cut" to access the basic features of SOS-Guardian, SOS-KidProof Lite, SOS Best Defense and SOS Pro such as Internet filtering utility. You can access this menu by "right-clicking" on the icon
    XFindfind.exeAdded by the OPANKI WORM!
    XFind FastFindfast.exeComplete utter waste of space! Part of MS Office - searches disk drives for Office file types to make opening them easier
    YFind Virus Launch Programfvlaunch.exePart of Dr. Solomon's Antivirus
    XFindHack[path to trojan]Added by the KELVIR-BA TROJAN!
    UFinePrint Dispatcher v4fpdisp4a.exeFinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. "FinePrint saves ink, paper, time and money by controlling and enhancing printed output"
    UFinePrint Dispatcher v4fpdisp4.exeFinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. "FinePrint saves ink, paper, time and money by controlling and enhancing printed output"
    UFinePrint Dispatcher v5fpdisp5a.exeFinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 5.x of the software. "FinePrint saves ink, paper, time and money by controlling and enhancing printed output"
    NFineReader7NewsReaderProAbbyyNewsReader.exeABBYY FineReader OCR software - version 7
    XFire Wall services[random filename]Added by the IRCBOT-QY WORM!
    ?FireBox Control PanelFireBox.exeControl panel for the Presonus FireBox firewire based music recording system. Is it required?
    XFireExplore UpdateFireExplore.exeAdded by a variant of the RBOT WORM!
    XFireFoxfirefox.exeAdded by the RBOT-ATP WORM! Note - this is not the popular FireFox web browser and is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    XFirefox Plugin Managerfirefoxpgm.exeAdded by the MSNPHOTO.E WORM!
    XFireFox Service Driversssmss.exeAdded by a variant of the SDBOT WORM!
    XFireFox Startup Driverswuaclt.exeAdded by the RBOT.BYX WORM!
    Xfirefox.exefirefox.exeAdded by the BANKER-EBO TROJAN! Note - this is not the popular FireFox web browser and is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    XFirewall wmlaunch .exeAdded by the ELIPTER.A or ELIPTER.B WORMS!
    XFirewallwmlaunch .exeAdded by the ELIPTER.D WORM!
    XFirewallSP2 UPDATE.exeAdded by the ELITPER.E WORM!
    XFirewallFirewall.batAdded by the YPSAN.G WORM!
    Xfirewallfw_304.exeAdded by the JQ TROJAN!
    XFirewall auto setupwinlogon.exeAdded by a TROJAN - see here. Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
    XFirewall Controlssys32.exeAdded by the SDBOT-DGI WORM!
    XFirewall PolicyMidiDef32.exeAdded by the PIEBOT-A TROJAN!
    XFirewall Sp2 systemsys32Conf.exeAdded by the RBOT-ABT WORM!
    XFirewall Update System1WinedowsUpdater1.exeAdded by the RBOT-ARU WORM!
    XFirewall Updatermsnupdateit.exeAdded by the RBOT-AAQ WORM!
    XFirewall.exeFirewall.exeAdded by the AGENT.AGL WORM!
    XFirewallActiviescsrss.exeAdded by the BANKER-AQ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "3041" subfolder
    UFirewallStartupFirewallstartup.exeInnovative Startup Firewall - "designed to protect your computer from programs that install themselves in the StartUp area of your Windows without asking for your approval. Innovative StartUp Firewall will help you keep your computer clean, fast and in it's best shape"
    XFirewallSvrFirewallSvr.exeAdded by the NETSKY.X or NETSKY.Y WORMS!
    Xfirewall_antifirewall_anti.exeAdded by the NETDENY-B TROJAN!
    XFireWire Driversamx.exeAdded by the SDBOT.AE WORM!
    XFireWire Servicenvscv32.exeAdded by a variant of the SDBOT WORM!
    XFireWire Servicesnvcsv32.exeAdded by a variant of the SPYBOT WORM!
    XFirst Home Pagehttp://find.naupoint.comNaupoint browser hijacker
    XFIXWinFIX1.0.vbsAdded by the GORMLEZ-A WORM!
    YFix-itmxtask.exePart of Ontrack's Fix-it Utilities Suite. Loads a System Tray icon that lets you access the full program. Needed if you run the crash guard, intellicluster, anti-virus, or autoupdater. Otherwise not required
    YFix-it AVmemcheck.exePart of Ontrack's Fix-it Utilities Suite anti-virus. Performs a quick check of memory for signs of any virus. Exits afterward and returns all resources used in one user's experience. Not required but could be left without a drain on resources
    Xfjdslssdfdmat2.exeAdded by the SLAPEW.C TROJAN!
    UFjMenuFjMenu.exeFrom the "Fujitsu Menu" tray icon you have instant access to the Control Panel, Tablet pc keyboard, Tablet and pen settings, Fujitsu display controls, brightness control, sounds and audio devices, capture screen, capture window, organize favorites, power options, printers and faxes, LCD brightness MIN, LCD brightness MAX, Enable/disable Button Panel and the Fujitsu menu settings, which are customizable
    UFJTWAIN SetupFjtwSetup.exeFujitsu scanner utility
    NFJUPDNV_Chitosefjdvrupd.exeDriver update for a Fujitsu Siemens Lifebook laptop
    XFKS v2.0msngr.exeAdded by an unidentified WORM or TROJAN!
    NfkSysMonfksysmon.exefkWrae SysMon - system monitor - "displays the current memory consumption, CPU and resource usage, date, time, Windows uptime, IP address and a lot more"
    XFlaCPYflacpy.exeFlashEnhancer adware variant
    XFlash Driver[path to trojan]Detected by PCTools as the AGENT.CWVT TROJAN! See here
    XFlash Media%%%%%.exeAdded by a variant of the IRCBOT TROJAN! See here
    XFlash Media%%%.exeAdded by a variant of the IRCBOT TROJAN! See here
    XFlash Media[path to trojan]Detected by Trend Micro as the IRCBOT.AUR TROJAN! See here
    XFlash Media^ ^^^ %% % ^% ^%%^ %^ .exeAdded by a variant of the IRCBOT TROJAN! See here
    XFlash Media^^% ^ %%% %^%%%^%%^%^% % ^^%% % %^^^^ ^%%^%% .exeAdded by a variant of the IRCBOT TROJAN! See here
    XFlash Media^^^^^.exeAdded by a variant of the IRCBOT TROJAN! See here
    XFlash Media^^^^^^.exeAdded by a variant of the IRCBOT TROJAN! See here
    XFlash Mediaservices.exeAdded by a variant of the IRCBOT TROJAN! See here. Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
    XFlash Mediazrpk??'?'%''msn'?%'fix''.exeAdded by a variant of the IRCBOT TROJAN! See here
    XFlash Player2[path to worm]Detected by Trend Micro as the IRCBOT.PD WORM! See here
    ?FLASH32-flash32.exe??
    XFlash32FLASH32.COMAdded by the STARTER-F TROJAN!
    UFlashEncFlashEnc.exeSupplied with EasyDisk USB pen devices. The utility manages the encryption and compressed folders options. It will create these folders if running on the USB key without permission, which is a pain. No need for it if you do not want these features
    NFlashgetFlashGet.exeFlashGet download manager
    XFlashget Download ManagerFlashget.exeAdded by the RBOT-AGZ WORM!
    UFlashMuteFlashMute.exe"FlashMute is a tool which allows you to mute/unmute Flash Movies loaded in a browser exclusively, or alternatively all sounds produced by the browser"
    NFlashPath MonitorSDSTAT.EXESystem Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
    NFlashPath MonitorFLSHSTAT.EXESystem Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
    NFlashPath StatusSDSTAT.EXESystem Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
    NFlashPath StatusFLSHSTAT.EXESystem Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
    XFlashy BotFlashy.exeAdded by the GLUPZY.A WORM!
    XFlash_Player_Installying.exeConstructor VC2000 malware
    XFlenCPYflencpy.exeFlashEnhancer adware variant
    UFlexicdFlexicd.exeCD player - part of the Win95 Power Toys
    UFlingRunfling.exeFling - free FTP software from NCH Software
    UFLMBROWSERMOUSEmouse32A.exeMouse utility for a Trust brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
    UFLMK08KBMMKEYBD.EXEMultimedia keyboard manager. Required if you use the additional keys
    UFLMK08KBKbdAp32A.exeKeyboard utility for a Medion brand (and possibly others) keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard
    UFLMLABTECMOUSEmouse32A.exeMouse utility for a Labtec brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
    UFLMMEDIONMOUSEmouse32a.exeMouse utility for a Medion branded Fellowes mouse
    UFLMOFFICE4DMOUSEmoffice.exeMouse utility for a Labtec brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
    UFLMOFFICE4DMOUSEmouse32a.exeMouse utility for a Micro Innovations brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
    UFLMTRUSTKBKbdAp32A.exeKeyboard utility for a Trust brand keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard
    UFLMTRUSTMOUSEmouse32a.exeMouse utility for a Trust brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
    XFlnCPYflncpy.exeFlashEnhancer adware variant
    XFLooDNeTFLooDeR.exeAdded by the ENDOOL TROJAN!
    XFloppy Master[path to trojan]Added by the ZONIT-F TROJAN!
    ?Flow Go TVflogotv.exe??
    Xflpsflps.vbsAdded by the BYRON WORM!
    Xflpycntlflpycntl.exeAdded by the CRYPTER.C TROJAN!
    ?FLSVCIFLSVCI.exe??
    YFltProcessmsinet.exePart of Cyber Patrol internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done
    XFlyswatDesktopflydesk.exeAdvertising spyware
    UFmctrlTrayFmctrl.EXEGenius SM-Live Control Panel. Enhances audio output through Genius sound cards (makes a big difference and worth the 3MB Ram used)
    Xfmnwebassistfmnwebassist.exeAdware popup generator
    UFMStartFmstart.exeGFI FAXmaker - native fax connector for Microsoft Exchange Server or for networks, allows all users to send and receive faxes right from their desktop
    XFMSZfmsz.exeAdded by the FMSZ TROJAN!
    Xfnmwebassistfnmwebassist.exeWinPL adware
    ?FocusFocus.exeISDN configuration wizard?
    XFolder Servicewssdtu.exeAdded by the MANIFEST TROJAN!
    UFolder Viewfolderview.exeFolder View enhances the Windows file Explorer by making all folders you need available in a single click
    UFolderClone v*.*.*folderclone.exeFolderclone backup and synchronization software
    XFolderRaper[path to worm]Added by the VB.GOZ WORM!
    UFolderShareFolderShare.exe"FolderShare allows you to create a private peer-to-peer network that will help you to synchronize files across multiple devices and access or share files with colleagues and friends"
    NFolding@homeWINFAH.EXEFolding@Home is a distributed computing project which studies protein folding, misfolding, aggregation, and related diseases - must be running in order to access the internet to upload to the servers. Available via Start -> Programs
    NFoneSyncSystemTrayFoneSyncSystemTray.exeSystem Tray icon for Nokia FoneSync utility for the 7160/7190 mobiles. Useful to send data from/to the cell phone and the computer. You can use it to backup data or even to input data through the computer keyboard (which naturally is much more comfortable). Run manually when required
    XFontFixfontfix.exeAdded by an unidentified VIRUS, WORM or TROJAN!
    NfontnavFontNav.exeFont Navigator from Bitstream Inc. - a font management utility
    XFontsLoaderldfnt32.htaUnidentified malware
    XFONTVIEWFONTVIEW.EXEAdded by the OPASERV.T WORM!
    UFooBar 1.0FooBar.exeFooBar - "combines fifteen high-quality productivity tools in a single toolbar that floats on your desktop or runs in the Windows task bar"
    Xfoobin lptt01adaware.exeRapidBlaster variant (in a "foo1" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
    Xfoobin ml097eadaware.exeRapidBlaster variant (in a "foo1" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
    YFoolProoffpwinldr.exeFoolProof Security PC security software from SmartStuff
    YFoolProofSweep??Part of FoolProof Security PC security software from SmartStuff
    NForbesForbesAlerts.exeForbes Business News Alerts - displays business news headlines in a little window on the screen
    XForceShowrundll32.exe QaBar.dll, ForceShowBarAdultLinks.QBar parasite related! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "QaBar.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    NForget Me NotAGRemind.exeCalendar reminder part of Broderbund's American Greetings? CreataCard?
    XFortiClientFortiClient.exeFortinet security systems are the new generation of real time network protection systems
    UFortis Secure Layer Configcseinst.exeFortis Bank Home Banking part. Installed during the installation of the software necessary to run the Home Banking. According to Fortis Bank this will not in any way be harmful to the system or relay system information
    NFotoStation Easy AutoLaunchFotoStation Easy AutoLaunch.exeInstalled with a Nikon digital camera. Used to collect photos uploaded from camera program NkVwMon.exe. If your camera is not connected (via USB port) you do not need this program loaded either
    UFoul PXFoulPX.exeFoul PX, Optusnet usage stat checker
    UFourthDayFourthDay.exeThe Fourth Day - "astronomical clock and almanac for your system tray"
    XFoWilCofowilco.exeAdded by the WOOTBOT.CR WORM!
    Xfoxdhfoxdhend.exeAdded by the MENGHUAN TROJAN!
    Xfoxdhfoxdh.exeAdded by the GWGHOST-Q TROJAN!
    Xfoxrxjhfoxrxjh.exeAdded by the GWGHOST-T TROJAN!
    Xfoxwudy9912service.exeAdded by the BANCOS-BT TROJAN!
    YFP Loaderloadfp.exeFoolProof Security - PC security software from SmartStuff
    ?FPWGMWZDFPWGMWZD.exe??
    NFpxmnmsrvc.exeRemote Desktop Sharing service part of Microsoft's Netmeeting allowing users to share items on their screens across remote locations
    Xfqorstub_113_4_0_4_0.exeTargetSaver adware
    XFrameWork 2.5FrameWork.exeAdded by the RBOT-FMW WORM! Note - can terminate AV related processes
    XFrancesvchost.exeAdded by the MIMAIL.L WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
    UFrapsfraps.exeFraps Real-Time Video Capture software
    NFree Download Managerfdm.exe"Free Download Manager" - see here
    ?Free Downloads Monitorfdcmon.exe??
    UFree Ram Optimizerfro.exeFree Ram Optimizer monitors your memory, and frees up ram if it falls below a certain minimum. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/ME. See this article and make up your own mind
    NFreebie NotesFreebieNotes.exeFreebie Notes by Power Soft - create electronic notes (stickers)
    YFreedomFreedom.exeFreedom Internet Security & Privacy - anti-virus, personal firewall and parental control. It also blocks ads, safeguards your personal information, encrypts your passwords, and much more. No longer available for sale
    UFreeMem ProFMEMPRO.EXEFreeMem Pro - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
    UFreeMemVn2FreeMem.exeFreeMem - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
    XFreeMP3downloadrundll32.exe MSA64CHK.dll, DllMostrarMatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder
    UFreeRAM XPFreeRAM XP Pro *.exeFreeRAM XP Pro - memory optimizer where * represents the version. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
    UFreeRAM XPFreeRAM XP Pro.exeFreeRAM XP Pro - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
    Xfreestylelockx.exeAdded by the RBOT-ATH WORM!
    Ufreesurferfs20.exeEMS Free Surfer mk II - pop-up stopper
    Xfreexstylelockbar.exeAdded by the LOXBOT.D WORM!
    Xfreexstylelockbr.exeAdded by the LOXBOT.C WORM!
    Xfreinstpgs.exeWinSpyControl spyware remover - not recommended, see here
    UFresh Desktopfreshdesktop.exeFresh Desktop is a utility that lets you manage vast collections of wallpapers for your desktop with ease. When run on bootup it changes the desktop wallpaper at startup or at specified intervals
    Nfreshclamfreshclam.exeAuto update agent of the open source Clamwin virus scanner
    ?frgukshdrkmck.exe??
    ?FridaysInHellInstallerFridaysInHellInstaller.exe??
    XFriendlyTypelsass.exeAdded by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder
    XFriendlyTypeNameservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
    XFriendlyTypeNamewinlogon.exeAdded by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
    NFriendlyWebQuick-LaunchSELFCERT.EXEselfcert.exe is a stand alone program for creating your own digital certificates for macros - the .exe is installed as an extra basically by clicking on MS Office in add/remove programs and selecting remove - also I would do away with the FriendlyWebQuickLaunchBar as well
    UFRISK FP-SchedulerF-Sched.exeScheduler for F-Prot anitvirus software. Leave enabled unless you scan manually on a regular basis
    ?FRITZ!DSL StartcenterStCenter.exeFRITZ! ISP software "StartCenter" User interface that allows you to manage, tweak and diagnose many aspects of your internet connection - is it required?
    UFRITZ!webProtectFwebProt.exeFirewall included in FRITZ! ISP DSL software
    NFromine WinPopupwinpopup.exeInstant Messenger program
    Xfroodytimoty.exeAdded by an unidentified malware
    XFrskfrsk.exeUnidentified adware downloader trojan
    Xfrunderc32xz.exeAdded by an unidentified TROJAN!
    YFRW_EXEFRW.EXEConSeal Signal9 firewall - now McAfee Personal firewall
    Yfrxmxinsfrxmxins.exeATI 3D Studio MAX/VIZ driver
    XFS Agentfagent.exeAdded by the VOLVER-B TROJAN!
    XFS6519FS6519.dll.vbsAdded by the SOLOW.B WORM!
    Yfsaafsaa.exeF-Secure antivirus Authentication Agent - creates and stores private keys used by a client to access servers
    NFSCBossFSCBoss.exeFree Store Club shop online software
    ?FSDPSRVFSDPSRV.exe??
    XFSHsvcnva.exeMalware, detected by Ewido Security Suite as TrojanDownloader.Delf.ks
    Ufspfsp.exeFolder Shield - hide entire directories and thus prevent access by anyone else to your personal files and documents
    YfsprFolderShield.exeFolder Shield - hide personal files and folders
    NFSScrCtlFSScrCtl.exeScreen saver control applet used by the "Stardust Screen Saver Toolkit" and "SolidWorks Screen Saver"
    Ufsservfserv.exeFarsighter Server - monitors a remote computer invisibly by streaming video to a viewer on your computer. You will know exactly what is happening on the remote computer as you see it in real-time
    XFSWFSW.exeFreeScratchAndWin parasite
    UFSWebServerfsws.exeEasy File Sharing Web Server is a Windows program that allows you to host a secure peer-to-peer and web-based file sharing system without any additional software or services
    XFtkCPYftkcpy.exeFlashEnhancer adware variant
    UFtLnSOP_setupFtLnSOP.exeFujitsu scanner utility
    UFTMSFLT(USB)FTMSFLTU.EXEFujitsu's Touch Panel Message Notifier
    XFTP FOR WINDOWSftpwin32.exeAdded by a variant of the RBOT WORM!
    XFTPGraberFTPGraber.exeAdded by the DLOADER-DT TROJAN!
    NFTPManagerFTPDM.exe"Robust FTP is a Windows-based file transfer client application that transfers files between a user's local PC and another, remote computer system connected via a modem and telephone lines or by a local-area network (with upload transfer resume and download transfer resume)". Can be started manually
    UFtpqueueFtpsched.exePart of WS_FTP Pro from Ipswitch. Queueing facility for scheduling FTP transfers
    ?FtpServer.exeFtpServer.exePart of Sharpdesk from Sharp Electronics Corp. "An easy to use desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents". Is it required?
    Uftutil2rundll32.exe ftutil2.dll, SetWriteCacheModeRelated to Promise Technology's FastTrak SX4030/4060 PCI ATA Raid 5 controller (and possibly others)
    XFuckD3w4FuckD3w4.exeAdded by the BRONTOK-DI WORM!
    XFuckerfucker.vbsAdded by the CATCHER-A WORM!
    UFujitsu Hotkey UtilityIndicatorUty.exeFujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook, eg, when you press the hotkey for muting the sound, a loudspeaker icon with a cross on it is displayed
    UFujitsu MenuFjMnuIco.exeFrom the "Fujitsu Menu" tray icon you have instant access to the Control Panel, Tablet pc keyboard, Tablet and pen settings, Fujitsu display controls, brightness control, sounds and audio devices, capture screen, capture window, organize favorites, power options, printers and faxes, LCD brightness MIN, LCD brightness MAX, Enable/disable Button Panel and the Fujitsu menu settings, which are customizable
    Xfukerservicefukerz.exeAdded by a variant of the RBOT WORM!
    XFUKLBARbar.exePurityScan/Clickspring adware
    XFunFun.exeAdded by the COIDUNG-A WORM!
    NFusionHdtvTrayFusionHdtvTray.exeFusionTrayAgent - main executable for DVICO FusionHDTV software. It adds an icon to system tray that allows you to easily access Fusion HDTV software
    UFusionRCFusionRC.exeRemote control manager for DVICO FusionHDTV
    UFusionRemoteFusionRc.exeRemote control manager for DVICO FusionHDTV
    NFusionTrayAgentFusionHdtvTray.exeFusionTrayAgent - main executable for DVICO FusionHDTV software. It adds an icon to system tray that allows you to easily access Fusion HDTV software
    Xfvekfvek.exeAdded by the DRIVOL-A TROJAN!
    YFveNotifyfveNotify.exeWindows Vista - BitLocker Drive Encryption Notification Utility. Available with Enterprise and Ultimate versions of Vista, "BitLocker prevents a thief who boots another operating system or runs a software hacking tool from breaking Windows Vista file and system protections or performing offline viewing of the files stored on the protected drive" - see here
    XFW Managerfwcheck.exeAdded by the DELBOT-H WORM!
    XFWDMON.EXEfwdmon.exeAdded by the PROXY-S TROJAN!
    Yfwenc.exefwenc.exeCheck Point SecuRemote VPN client - "dynamic and fixed IP addressing for all ISP services - dial-up, cable modem, or DSL - the ideal solution for telecommuters and mobile workers"
    XFwr Command Modulefwr.exeAdded by the SDBOT-PP WORM!
    Nfwrastrcfwrastrc.exeDial-up software for Friendly Technologies/1NationOnLine free ISP
    UfwservicefwserviceeAcceleration Stop-Sign security software related. Previously not recommended, see here
    XFXieloader.exeAdded by the SMALL.RR TROJAN!
    Ufxredirfxredir.exeCanon MultiPASS fax redirector
    Xfzgsvhost32.exeAdded by the DLOADER.BDK TROJAN!
    Xf~ara32.exeAdded by the CAY TROJAN!
    Xg.exeg.exeAdded by the GRAYBIRD.Q TROJAN!
    XG00123[worm filename]Added by the BUGBROS WORM!
    XG0mezG0mez.vbsAdded by the GORMLEZ-A WORM!
    XG3GSMedia3.exeMalware downloader - detected by Kaspersky as the VB.UX TROJAN!
    ?g3dctlg3dctl.exe??
    ?GACServiceGACService.exeRelated to a Gemplus product. What does it do and is it required?
    Xgadkgak12fsafsakx12.exeAdded by the ONLINEG-N TROJAN!
    NGadu-Gadugg.exePolish language Instant Messaging client
    NGadwin PrintScreenPrintScreen.exeGadwin PrintScreen - utility to capture, print or save the current window
    XGAELICUM.EXEGAELICUM.EXEAdded by the PENTA-A TROJAN!
    Xgah95on6gah95on6.exeShopAtHome/SAHagent adware
    Ugaimgaim.exeGaim is an instant messenger client with capability to connect to AIM, ICQ, MSN Messenger, Yahoo, IRC, Jabber, Gadu-Gadu and Zephyr networks
    UGainwardTBPanel.exeConfiguration utility for Gainward graphics cards. Not required unless you use non-default settings. Available via Start -> Settings -> Control Panel
    Xgameshit.exeAdded by the Netclap Gold backdoor TROJAN!
    Xgamepatcher.scrAdded by the PSW-ED TROJAN!
    NGame DeviceJOYUPDRV.EXEGenius game controller profile activator
    XGame HouseGameHouse.exeAdded by the DELF-DRA WORM!
    NGameDriveGDTask.exeGameDrive Virtual Driver from FarStone Technology, Inc. Run PC games without the disc
    XGames Accelerationsvshost.exeEasySearch adware
    XGames Acceleration[path to trojan]Added by the SMUTSRCH-A TROJAN!
    XGames Accelerationsvshost1.exeAdded by the DLOADR-AWD TROJAN!
    XGames toolbarrundll32.exe [path] tbGame.dll, DllShowTBTopconverting.com180Search "Games Toolbar" adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
    NGameSpotkontiki.exeKontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops
    Ugameutil.exegameutil.exePart of Redline RegTweak as supplied with Sapphire ATI graphics cards. You can configure different overlclocking settings on a per game basis and this sets those conditions following a re-boot
    Xgammasvchost.exeAdded by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
    UGammaHotKeyssetgamma.exePart of the RadeonTweaker program for adjusting ATI Radeon graphics cards. Allows you to adjust the gamma (or brightness) when playing a full-screen game without switching back to the desktop
    UGARO Status Monitorcnwism.exePrint monitor for certain Canon printers
    XgaSrvgaSrv.exeAdware downloader, identified by Panda antivirus as Trojan.Downloader.ALQ
    XgaSrvegaSrve.exeAdware downloader, identified by Panda antivirus as Trojan.Downloader.ALQ
    XGate Personal FirewallSystpl.exeAdded by the RBOT.ADC WORM
    NGateway Extended WarrantyGWCares.exeGateway Extended Warranty reminder
    XGatorgator.exeGator eWallet adware. Please note that Claria Corporation no longer support GAIN-Supported software - see here
    XGator eWalletgator.exeGator eWallet adware. Please note that Claria Corporation no longer support GAIN-Supported software - see here
    XGay_Sexy_**Gay_Sexy_**.exePremium rate adult content dialler (where * is a random char)
    UGazelDisplaygsyno.exeBT Digital Access USB - Gazel ISDN installation System Tray icon
    YGBMHome7AgentGBMAgent.exeGenie Backup Manager Home 7 - backup software
    YGBMLite7AgentGBMAgent.exeGenie Backup Manager Lite 7 - backup software
    YGBMPro7AgentGBMAgent.exeGenie Backup Manager Pro 7 - backup software
    YGBSpaceManSpaceMan.exeGreenBorder - secure your browsing activities on the internet
    UGBTrayGBTray.exeSystem Tray icon access to Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
    XgCacgcac.exeAdded by the TACTSLAY.U TROJAN!
    XgcasDtServgcasDtServ.exeAdded by an unidentified WORM or TROJAN. Note - this is not related to Microsoft Antispyware which has a process bearing the same name which doesn't appear as a startup
    UgcasServgcasServ.exeGiant Antipsyware - now superseeded by Microsoft Windows AntiSpyware
    XgcasServrealsched.exeAdded by a variant of the TACTSLAY.A TROJAN! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name
    ?GCC Remindergccrem.exeAssociated with AcraMax Greeting Card Creator. Is it a registration reminder?
    NGCSGrabClipSave.exeGrabClipSave screen capture tool
    XGDAX[path to backdoor]Added by the RANKY.K TROJAN!
    XgdcwGDCW.exeWinAnonymous spyware remover - not recommended, see here
    Xgdien32gdien32.exeAdded by the SINGU-P TROJAN!
    Xgdimxgdimx.exeMPB-D dialer. Note - provides an uninstall option which can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as "gdimx"
    UGDMgr.exegdmgr.exeGuardMon is a commercial surveillance software program designed to monitor all forms of user activity on a computer
    NGDriveGDriver.exeFound on IBM systems. All it does is set the CDROM drive letter to G:. Set your drive letter manually via Start -> Settings -> Control Panel -> System -> Device Manager
    NGearboxconfsvr.exeNTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which can be used instead using the dial-up details available here
    NGEARsecgearsec.exeInstalled by Apple Quicktime package - iPod/iTunes CDRW support. Can be disabled if you only require Quicktime player
    XGEDZACGEDZAC.exeAdded by the GEMEL WORM!
    XGekio Startupsgnksvc32.exeAdded by the AGOBOT.AFJ WORM!
    NGemStRmWGemStRmW.exeFor a GemPlus smart card reader. If it doesn't start automatically when you insert the smart card, start it manually
    Xgencrootgencroot.exeAdded by the SDBOT-AED WORM!
    UGene USB MonitorUSBMonit.exeMonitors USB ports for insertion of Sandisk USB flashdrives
    Xgeneral lptt01general.exeRapidBlaster variant (in a "General" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
    Xgeneral ml097egeneral.exeRapidBlaster variant (in a "General" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
    XGeneric host proccess for windowsSVCHOSTS.EXEAdded by the SPYBOT-GQ WORM!
    XGeneric Host ProcessSCHOST.EXEAdded by the RBOT-NC WORM!
    XGeneric Host Processsvchost.exeAdded by the DLOADER-NX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
    XGeneric Host Processcamacttiv.exeDetected by AVG Anti-Spyware as the CIADOOR.13 TROJAN!
    XGeneric Host Process for Win32 Servicesvlhost.exeAdded by the WOOTBOT.EX WORM!
    XGeneric Host Process for Win32 Servicesvchost.exeAdded by the SPYBOT.NC WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
    XGeneric Host Process for Win32 Servicesntspcv.exeAdded by the SDBOT.S TROJAN!
    XGeneric Host Process for Win32 Servicesintspvc.exeAdded by the DINFOR.D WORM!
    XGeneric Host Process for Win32 Serviceswinsvc.exeAdded by the SDBOT-O WORM!
    XGeneric Host Process for Win32 Servicesbazzi.exeAdded by the AHKER.E WORM!
    XGeneric Host Process for Win32 Serviceswinsvc32.exeAdded by the SDBOT-P WORM!
    XGeneric Host Process for Win32 Serviceslspsvc.exeAdded by the MUMU.C WORM!
    XGeneric Host Process for Win32 ServicesSPSVC.EXEAdded by the SDBOT.DA WORM!
    XGeneric Host Process for Win32 Servicessvchost32.exeAdded by the AGOBOT.ALH WORM!
    XGeneric Host Process for Win32 Servicessv?h?st.exeAdded by the DLOADER.AK TROJAN!
    XGeneric Host Process for WinXP Servicesmshelp.exeAdded by the AGENT-GQP TROJAN!
    XGeneric Host Process2 System Backupscvhost2.exeAdded by the RBOT-BAH WORM!
    XGeneric Host Process326a System Backupscvhost326a.exeAdded by a variant of the SDBOT WORM!
    XGeneric Host Servicelshost.exeAdded by the RBOT.LU WORM!
    XGeneric Service Processregsvc32.exeAdded by the GAOBOT.UJ or GAOBOT.UL WORMS!
    XGeneric Service Processserv1ces.exeAdded by the AGOBOT-JK WORM!
    XGeneric Service Processnvsvc.exeAdded by the AGOBOT.BY WORM! Note - this is not the valid NVIDIA Driver Helper Service and is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    XGeneric Services Processregsvc32.exeAdded by the GAOBOT.SY WORM!
    XGenericHostXPWinLoaderXP.exeAdded by the BDOOR-ACX TROJAN!
    YGenie USB MonitorUSBmonitor.exePort monitor for an external USB hard drive. Required to enable access to the drive
    XGeography TX 1.0 NTCompuSpeed.vbsAdded by the NEWLEY-A WORM!
    XGerenciamento de arquivos do WindowsWinmod32.exeAdded by the DLOADER-WG TROJAN!
    Xgerman.exewinsystems.exeAdded by the BAGLEDl-AE TROJAN!
    Xgerman.exewintems.exeAdded by the BAGLE-AS TROJAN!
    XGestionnaire de disques universelsysoobe.exeAdded by the TOADER-A TROJAN!
    NGet Smilegetsmile.exePuts smilie faces in your E-mail. Run manually when required
    XGet-Torrent Servicewakeservice.exeGet-Torrent bittorrent client - Installs LOP adware
    YGetcaInfoMyCa.exeMonitor for a Belkin USB Wireless adapter
    XGetMP3rundll32.exe MSA64CHK.dll, DllMostrarMatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder
    NGetRight Tray IconGETRIGHT.EXEGetRight from Headlight Software - download manager for resuming downloads and choosing multiple download locations. The freeware version is/was spyware. The registered version isn't if you don't install the Aureate/Radiate software. Available via Start -> Programs
    XGetTheMusicrundll32.exe MSA64CHK.dll, DllMostrarMatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder
    XgetwinwinB_.exeAdded by the BANKER-HS TROJAN!
    Xgf1.0.0.2ggf.exeAdded by the EDFON.A TROJAN!
    Xgfxtrayrundll32 ctccw32.dll, findwndDetected by Kaspersky as the AGENT.AOU TROJAN! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
    UGhostSecuritySuitegss.exeGhost Security Suite - protect the registry from unauthorized reading and modification and other tools
    NGhostStartServiceGhostStartService.exeRequired to run the Windows based wizard in Norton Ghost - added from the 2003 version. Will start automatically when you run the wizard
    NGhostStartTrayAppGhostStartTrayApp.exeSystem Tray access to Norton Ghost - added from the 2003 version
    ?GhostSurfDelSatelliteDeleteSatellite.exeSpyCatcher spyware remover related. What does it do and is it required?
    YGhostSurfDelSatelliteDeleteSatellite.exePart of SpyCatcher spyware remover from Tenebril. Prevents rogue programs from sending personal information to a remote user via the Internet. If you use SpyCatcher with real time scanning, you'll want to leave this file in place
    Xgigabit.exegigabit.exeAdded by the BEAGLE.U WORM!
    XGigaByteCheatle.exeAdded by the SHODI.B VIRUS!
    YGilat SOM Enumeratordllhost.exeFor Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
    YGilatFTCftc.exeFor Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
    Xgimmygames[path to trojan]Added by the DLOADR-LN TROJAN!
    Xgimmysmileysgimmysmileys.exeGimmySmileys adware
    XGinaDllntgina.dllAdded by the ANIG.A WORM!
    ?GisdnLoggisdnlog.exeBT Digital Access USB
    UGlass2kGlass2k.exe"Glass2k is a small little program that allows Win2K/XP users to make any window transparent"
    XGLF Network Lan MonitorNPFMNTOR.exeAdded by the RBOT-AGY WORM!
    YGlideGlidew32.exeCirque touchpad driver
    XGlobal StartupWinDash.EXEDetected by Kaspersky as the VB.Q WORM!
    XGlobalSCAPE[random filename]Added by the RBOT-AYM WORM!
    XGLSetIT32msiexec16.exeAdded by the OPTIX PRO TROJAN!
    XGLSetIT32isass.exeAdded by a variant of the OPTIX PRO TROJAN!
    XGLSetT32smsiexec.exeAdded by the OPTIX-D TROJAN!
    ?gluongluon.exeIn a gluon/bin sub-directory
    Xglvglv.exeAdded by the DLOADER-NG TROJAN!
    XGMedia2GSM2.exeMalware downloader - detected by Kaspersky as the VB.UX TROJAN!
    XGMedia2GSMedia3.exeMalware downloader - detected by Kaspersky as the VB.UX TROJAN!
    YGmouseGmouse.exeAmouse mouse driver - required if you use non-standard Windows driver features
    UGnetmousgnetmous.exeGenius NetScroll+ mouse driver - required if you use non-standard Windows driver features
    UGNETMOUSEgnetmouse.exeGenius mouse driver - required if you use non-standard Windows driver features
    XGNP Generic Host Processsvchost.exeAdded by the ZAPCHAS TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
    XGNP Generic Host Processsvchost.exeAdded by the ZAPCHAS-R TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup and is always located in the System32 folder. This worm file is found in the System folder
    XGNP Generic Host Processsvchost.exeAdded by the ZAPCHAS-AA TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This one replaces svchost.exe in the System32 folder with a copy of Mirc on (NT/2K/XP) systems and just adds svchost.exe to the System folder on (9x/Me) systems
    ?gnubgnub.exe??
    Xgocvir.exeAdded by the SILOV-A WORM!
    XGo!Zillagozilla.exeDownload manager for resuming downloads and choosing multiple download locations. Advertising spyware
    XGo!Zilla Monster DownloadsGo.exeDownload manager for resuming downloads and choosing multiple download locations. Advertising spyware
    UGoBackGBMenu.exeRoxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
    UGoBackGBTray.exeSystem Tray icon access to Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
    UGoBack Polling ServiceGBPoll.exeRoxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
    UGoBack Tray IconGBTray.exeRoxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
    XGOGGOG.exeAdded by the PHILIS.B VIRUS!
    Xgoidrgoidr.exeGoidr adware
    UGoldensoft_MndlSvrMndlSvr.exeGoldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive, users can simultaneously access as many as 23 virtual CD-ROM drives at a speed of 200X for true multitasking
    XGolumservices.exeAdded by the GOLUM.A TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
    Xgolummservices.exeAdded by the DLOADER-ET TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "golumm" subfolder
    Xgoodbadvir.exeAdded by the SILOV-B WORM!
    Xgooglegoogle.exeAdded by the RBOT-AMW WORM!
    UGoogle DesktopGoogleDesktop.exeGoogle Desktop Search - "a desktop search application that provides full text search over your email, computer files, chats, and the web pages you've viewed. By making your computer searchable, Google Desktop Search puts your information easily within your reach and frees you from having to manually organize your files, emails, and bookmarks"
    NGoogle Desktop SearchGoogleDesktop.exeGoogle Desktop Search - "a desktop search application that provides full text search over your email, computer files, chats, and the web pages you've viewed. By making your computer searchable, Google Desktop Search puts your information easily within your reach and frees you from having to manually organize your files, emails, and bookmarks"
    XGoogle Earth[random filename]Added by the RBOT-AXK TROJAN!
    NGoogle Earth ViewerGOOGLEMAPS.EXEGoogle Earth "combines satellite imagery, maps and the power of Google Search to put the world's geographic information at your fingertips"
    UGoogle IME AutoupdaterGooglePinyinDaemon.exeGoogle Pinyin Input Method Editor (IME) - allows a user to input Chinese characters by entering the pinyin of a Chinese character (with or without tone, depending on the system) and then presenting the user with a list of possible characters with that pronunciation
    Xgoogle Intrenet Explorergoogle.pifAdded by the RBOT-ARA WORM!
    XGoogle serviceGooglesetup.exeAdded by the IRCBOT-RJ WORM!
    XGoogle Service FRGO0GLEFREE.EXEAdded by a variant of the SPYBOT WORM!
    Xgoogle toolbarggtb32.exeAdded by the AGOBOT-RR WORM!
    NGoogle UpdaterGOOGLE~1.EXEDownloads and installs updates for Google applications (Google Earth, Google Desktop, etc.)
    NGoogle UpdaterGoogleUpdater.exeDownloads and installs updates for Google applications (Google Earth, Google Desktop, etc.)
    XGoogleBot.exeGoogleBot.exeAdded by the GB TROJAN!
    NGoogleDCClientGoogleDCC.exeGoogle Compute Client - only present if you installed the Google Toolbar with "Google Compute" client active. Does complex calculations in the background when idle. If you want to turn it off go to your browser, click on the little double-helix on the Google Toolbar, and click "Stop Computing". No longer supported
    Ugoogletalkgoogletalk.exeGoogle Talk "enables you to call or send instant messages to your friends for free-anytime, anywhere in the world". Can be launched manually
    UGoToMyPCg2svc.exeExpertCity GoToMyPc logon - web-based remote-access solution that allows individuals and companies to register their computers online and then securely access those computers from any web browser
    XGotSmileyGotSmiley.exeGotSmiley - ad supported program that provides the user with smileys for use in emails. Not recommended. Please note that Claria Corporation no longer support GAIN-Supported software - see here
    Xgouday.exereadme.exeAdded by the BEAGLE.C WORM!
    XGPLv3[random name].dllVundo adware
    Xgpmcewindow.exeDetected by Kaspersky as the VB.CK WORM! See here
    NGRAgra.exeLooks at system resources at startup and warns you if they have dropped. Contains links to the Disk Clean Up, Defrag and Start Up Menu. It does have a link to a startup configuration utility. Similar to msconfig but can keep a list of disabled apps. Not really necessary. Only appears if you load the Gateway Startup Utility
    ?gramdate2Stop.exe??
    XGraphic Driversmss32.exeAdded by a variant of the RBOT WORM!
    XGraphic Loaderntvdm32.exeAdded by a variant of the RBOT WORM!
    XGraphic Updateopenglx.exeDetected by PCTools as the IRCBOT.BIM TROJAN! See here
    XGraphics_default.pifAdded by the AUTOSKY WORM!
    XGraphics adapter servicewindll.exeAdded by the ATNAS.A WORM!
    UGravis Appawareloaderdbserver.exeLooks like it's associated with Gravis game controllers and the Keyset Manager, allowing the user to program the buttons for games that don't support them
    UGravis Xperience Driver SupportGrxp4exe.exeDriver for Gravis game controllers such as the Eliminator Aftershock. Must be loaded if you run the supplied application software for the controller to be recognized. Start it manually via a shortcut if not used
    ?GrdSys32GrdSys32.exeX-Stream ISP software. Offers free Net access funded by on-screen ads. Is it required or can you create your own dial-up networking connection to use on demand?
    XGreasyPalmUpdateGreasyPalmUpdate.exeSearchFast adware
    NGreetings WorkshopGWREMIND.EXEYou really want to be reminded about somebody's birthday at the expense of resources?
    Xgremierwscript.exe gpremier.vbsAdded by the GPREMIER WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "gpremier.vbs" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    XGremlinintrenat.exeAdded by the DOOMJUICE WORM!
    NGroksterGrokster.exeGrokster Peer-To-Peer File Sharing program
    YGroove Virtual OfficeGroove.exe"Groove Virtual Office uses a peer-to-peer networking model to connect users in Groove Workspaces. In these workspaces geographically dispersed coworkers can do almost everything they could do in the same office. They can hold online meetings, store files and folders, save threaded discussions, scribble on whiteboards, share calendars, and track project information and timelines." Formerly by Groove Networks - now owned by Microsoft and part of MS Office
    YGrooveMonitorGrooveMonitor.exeMicrosoft Office Groove 2007 - Groove Folder Sharing synchronization (GFS). If you kill it, your GFS workspaces may not synchronize properly (particularly around unread-marks), and you might experience some nagging discomfort
    NGrpConvgrpconv.exeMicrosoft Windows Program Group Converter - used by installers (ONLY in the RunOnce keys) - provides the translation of groups and group items to folders and links. Also see this MS Knowledge Base article
    XGsAdsgms2.exePacerD_Media/Pacimedia.com adware
    ?GscbcGscbc.exe??
    Xgshpzzgshp.vbsHomepage hi-jacker
    NGsiconexeGsicon.exeADSL modem monitor from Eicon Networks (as used by BT for its Broadband internet service for example). Can safely be disabled without affecting the connection - all this does is give an indication of connectivity and access to the diagnostic facilities
    ?GsiFinalrundll32 gspndll.dll, postInstall finalUSB DSL modem related - [what does it do and is it required in startup?
    ?GSISETUP[path] GsiInst.exe INSTALL [path] V205Res 13BT Voyager ADSL modem related - what does it do and is it required?
    NGSOrganizerGSOrganizer.exeGoldenSection Organizer (now WinOrganizer - personal information manager
    Xgssomaticgssomatic.exeSearchcentrix hijacker
    YgStartgStart.exegStart GPS software from Garmin
    XGStartupGMT.exeGator spyware component - see here. Please note that Claria Corporation no longer support GAIN-Supported software - see here
    Xgsvgsv.exeAdded by the ROBAL 1.0 backdoor TROJAN!
    XGTGT.EXEAdded by the SDBOT-AJ WORM!
    UGTVEpgGTVEpg.exePart of Got All Media - control your TV tuner and other utilities from your PC
    XGTVRecGTVRec.exePart of Got All Media - control your TV tuner and other utilities from your PC
    NGtwatchgtwatch.exeAssociated with a Mustec scanner and not required
    Xgtydfiisca.exeAdded by the CLAGGER-BB TROJAN!
    Xgtydfiscca.exeAdded by the DWNLDR-GTK TROJAN!
    Xgtydfggrrgg.exeAdded by the DLOADR-AZK TROJAN!
    UGuardGuard.exeRelated to Phoenix Technologies Core Managed Environment (cME) Integration and Certification program
    NGuardianCMGrdian.exeMcAfee's QuickClean, an offline version of the one in their online Clinic. Normally run offline and not needed. Incidentally, incorporates more cleanup programs than the likes of WinOptimizer and System Mechanic
    UGuardian PC Security ToolsPfft.exeBoomerang Software's Guardian PC Security Tools - now rebranded as the eXtendia Security Suite
    Xguarnsetguarnset.exeAdlogix adware
    Xgummygummy.exeAdded by the VANEBOT-AQ WORM!
    XGURLgurl.exeGURLWatcher spyware
    UGuruNetGuruNet.exeGuruNet lets you click on any word on your screen to get the relevant information you want
    XGustavVED[filename].exeAdded by the OPASERV.H WORM!
    Xgvagfxjrundll32 ...gvagfxj.dllUnidentified adware, spyware or virus
    Ygw port controllerPORTCT95.EXEFrom a visitor - "I must keep it active in start up or my Lexmark printer and RCA Cam program cannot discover a working port to work". From the file properties, the file is known as "Smart Thru Fax Drive Spy" and is supplied by Samsung
    NGWInkMonitorGWInkMonitor.exeGateway ink monitor - makes an annoying popup that says your printer may be running out of ink, do you want to buy some!
    Xgwizntsystem.exeAdded by the NITWIZ.A TROJAN!
    Xgwizarpl.exeDetected by F-Prot as W32/Downloader-Sml-based
    NGWMDMMSGGWMDMMSG.exeUsed with internal modems on Gateway and vprMatrix PCs. This is the "GTW modem messaging applet" and is not required for the modem to work correctly
    UGWMDMpiGWMDMpi.exeUsed with internal modems on Gateway PCs such as the 450SX Notebook. Required for audio settings to be maintained and does not remain in memory once run. See here for more information
    Ugwumgwum.exeGigabyte utility manager. Loads if you have a Gigabyte motherboard and got a full bundle of utilities installed. Monitors CPU, fans, BIOS etc. Only used by system "tweakers"
    ?gyygyy.exePossibly Gator (and therefore spyware) related?
    XG_Server.exeG_Server.exeAdded by the FEUTEL-C TROJAN!
    XG_Server1.2.exeG_Server1.2.exeAdded by the GRAYBIRD-Z TROJAN!
    UH/PC Connection AgentWCESCOMM.EXEActive sync for use with Windows CE based palm PC
    YH2Ocledx.exeRelated to copyright protection products by SyncroSoft
    UH2OWIBUCXWibu.exeRelated to CodeMeter from WIBU-SYSTEMS AG. Software protection hardware
    Xh4te Service Driversh4te.exeAdded by a variant of the RBOT WORM!
    Xhachimitsu-lemonhachimitsu-lemon.exeAdded by the HACHILEM TROJAN!
    XHackMuFptHackMuFpt.exeAdded by the SCLOG-AG TROJAN!
    Xhagentavp.exeAdded by the "Herman Agent" remote access TROJAN!
    UHalifaxHowardClusterskinkers.exe"Howard the Weatherman" desktop client from Halifax by Skinkers - marketing/messaging tool. Leave enabled if you want to receive messages
    YHamachihamachi.exeLogMeIn Hamachi remote control and VPN software
    UHaMFrontPanelhampanel.exeDisplays a panel simulating modem lights for the Intel HaM internal modem. The lights are useful as a reminder to disconnect from the net if you are likely to forget, but otherwise pointless
    UHandy Backup 3.9hbagent.exeHandy Backup - automatic backup of your critical data to virtually any type of storage media including CD-RW devices and remote FTP servers
    XHanUpdatehanz.exeAdded by the RBOT-GLJ WORM!
    NHard Disk SentinelHDSentinel.exeHard Disk Sentinel - a multi-OS hard disk drive monitoring application. Its goal is to find, test, diagnose and repair hard disk drive problems, display hard disk health, performance degradations and failures
    XHard drive Controllerhdcontroller.exeAdded by the KIMAN.B WORM!
    UHardware DoctorHwdoctor.exeWinbond Hardware Doctor - as included on some motherboard using Winbond's hardware monitoring chips. Displays fan speeds, voltages, temperatures. Only required if you're concerned about your system temperature - typically for "overclocked" systems
    XHardware Monitor Servicemshms.exeAdded by the WOLLF-A TROJAN!
    XHardware Profilehxdef.exeAdded by a variant of the LOVGATE WORM!
    XHardware Profilehxdef.exe...Added by a variant of the LOVGATE WORM!
    UHardware Sensors Monitorhmonitor.exeUtility to monitor fan speed and temperatures - similar to Motherboard Monitor. Only required if you're concerned about your system temperature - typically for "overclocked" systems
    XHardware Shell DetectionWinHSD.exeAdded by a variant of the RBOT WORM!
    UHarehare.exeHare - improve and optimize performance of desktop/laptop PCs
    XHATAPE[path to trojan]Added by the BANKER-QF TROJAN!
    UHawkEyeHAWK_95.EXEControl Panel application for the old Number Nine graphics cards to change resolution, colour depth, etc. Available via Start -> Programs
    UHawkEye IV Control PanelHAWK_32.EXEControl Panel application for the old Number Nine graphics cards to change resolution, colour depth, etc. Available via Start -> Programs
    XHbinstHbinst.exeHotbar adware
    NHC Reminderhc.exeFor Compaq PC's. Help Compiler, crunches help database, will run without being in startup when needed
    NHCDetectHCDetect.exeMS HomeClick Network - simple home network setup and configuration program included with 3Com HomeConnect home networking products. Runs in the background for network printer notification, detection, and Internet Connection Sharing (ICS) taskbar icon. Not required - network can be set-up manually, also has a known memory leak problem
    Uhcentertgcmd.exeSee also TgAddServer. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation
    Xhclean32.exehclean32.exeWareout - malware masquerading as a spyware and dialer remover
    UHcontrolhcontrol.exeHotkeys on an ASUS Notebook. Only required if you use the additional keys
    Nhcsystrayhc_tray.exeKuma Notifier for the Shootout! game from the History Channel. "It lets you know whenever there?s a new episode that?s been released or an announcement from the Kuma team. Just click it to get up-to-the-minute game and event information"
    NHDAShCutHDAShCut.exeHigh definition audio page shortcut for Realtek audio devices - not required
    XHDAudiohda.exeAdded by the TACTSLAY.U TROJAN!
    XHDAudio Driver 1.0[random filename].exeAdded by the TEADOOR-D TROJAN!
    XHDAudio Driver 2.0[random filename].exeAdded by the TEADOOR-E TROJAN!
    UHDDHealthhddhealth.exeHDD Health is a "full-featured failure-prediction agent for machines using Windows 95, 98, NT, Me, 2000 and XP. Sitting in the system tray, it monitors hard disks and alerts you to impending failure"
    UHDDlifeHDDlife.exeHDDlife checks the health of your hard drives at regular intervals and informs you about the results of these checks
    ?HDhelptbhdhelp.exeAssociated with Philips Edge series soundcards. Is it required?
    Xhdlfoe df98ndfsvchots.exeAdded by a variant of the RBOT WORM!
    Xhdlpscom[8 random letters].exeAdded by the RBOT-FUL WORM!
    NHDtrayHDtray.exePhilips Edge Series Control Panel Tray Utility - system tray icon for a Philips Edge series soundcards. Available via Start -> Settings -> Control Panel
    Xhe3bbcffrundll32.exe he3bbcff.dll, EnableRunDLL32LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "he3bbcff.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    Xhe3e3fc4rundll32.exe he3e3fc4.dll, EnableRunDLL32LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "he3e3fc4.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    XHELLBOT TEST1hellbot.exeAdded by the MYDOOM.BO WORM!
    XHELLBOT3coolbot.exeAdded by the MYTOB.AB WORM!
    Xhellfiresvchost.exeAdded by the LEOX.D TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
    Xhellodollyshost.exeAdded by the YODO WORM!
    Xhelloworldnb32ext2.exeAdded by the MYDOOM.BV WORM!
    Xhelloworldnb32ext3.exeAdded by the MYTOB.JT WORM!
    Xhelloworld3nb32ext4.exeAdded by the RITDOOR.A WORM!
    ?Helphelpext.exe??
    Xhelphelp.scrAdded by the BANCOS-BBU TROJAN!
    XHelpWizardnil.exeAdded by the BANCOS-BCZ TROJAN!
    XHelp and Support Serviceusnsvc.exeDetected by Kaspersky as the SDBOT.AAD TROJAN! See here
    XHelp Temp Filesnetreg.exeAdded by the FORBOT-EM WORM!
    Xhelpctl.exehelpctl.exeAdded by the GASLIDE TROJAN!
    XHelpereschlp.exeAdded by the BLASTER.T WORM!
    XHELPERgreece nm.exeAsdPlug premium rate adult content dialer variant
    XHELPERNetherlands.exeAsdPlug premium rate adult content dialer variant
    XHELPERnew zealand.exeAsdPlug premium rate adult content dialer variant
    XHELPERsweden.exeAsdPlug premium rate adult content dialer variant
    XHELPERcanada.exeAsdPlug premium rate adult content dialler variant
    XHELPERfrance.exeAsdPlug premium rate adult content dialler variant
    XHELPERtemp532.exeAsdPlug premium rate adult content dialler variant
    Xhelper.dllrundll32.exe [path] helper.dllCnsMin (Chinese Keywords) hijacker related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
    XHelpExp.exeHelpExp.exeAttune HelpExpress - spyware. Disable and uninstall - see here
    Xhelpmanagerspoler.exeAdded by the RANDEX.J WORM!
    Xhelpohelpo.exeAdded by the BANLOA-BU TROJAN!
    Xhelpwhelpw.exeAdware downloader
    Xhen[filename].exeAdded by the TARNO.G TROJAN!
    Xheomstoolheomstool.exeAdded by the HEOMS TROJAN!
    XhErcUnessofthost.exeAdded by the GARROCH WORM!
    UHermes MessengerDGDRHE~1.EXEA LAN messenger alternative to WinPopUp - Digital Dreams Software
    XHewlett Packard Managerhpmanager.exeAdded by the MYTOB.KE WORM! Note - this is not a valid Hewlett-Packard program
    NHewlett Packard RecorderRemind32.exeHP multifunction registration
    UHfHf.exeHide Folders - hide your folders so only you can view them
    XHF Securityhfsecure.exeAdded by the AGOBOT-TI WORM!
    Uhffsrvhffsrv.exeHide Files & Folders is a "password-protected security utility working at the Windows kernel level allowing you to password-protect files and folders, or to hide them securely from viewing and searching"
    Uhfxphfxp.exeHide Folders XP - hide your folders so only you can view them
    Xhgqhp.exehgqhp.exeAdded by the FLUSH.F TROJAN!
    NHGTXPEIFirstReboot.exeHerucles Audio tool for the Hercules Game Theater XP soundcard. Available via Start -> Settings -> Control Panel
    Xhhtnsnrnxntup.exeAdded by a variant of the ORCU.B TROJAN!
    ?HiberMonitorHCount.exe??
    UHibernationhib32.exeReduces the power consumption when the laptop isn't being used to preserve battery power. Similar programs on other laptops reduce the processor clock rate, etc. Required if you run of battery regularly
    XHid.exehid.exeAdded by the RATSOU.B TROJAN!
    UHideOEHideOE.exeHideOE - allows you to 'hide' Outlook Express or minimize it to the System Tray
    XHideRun.exeHiderun.exe and svhost.exe and pro.gifAdded by the BOOHOO WORM!
    XHideStyleAnte Browse Trust.exeIE toolbar taking you to Lop.com. If the exe is running, end it and remove the "Stupidmore" directory from C:Program Files
    Uhidservhidserv.exeThis is the Human Interface Device Server for Win98SE/2000/Me/XP, it is required only if you are using USB Audio Devices you can disable via Msconfig. See here. Typical examples are USB multimedia keyboards with volume control and web-ready keyboards. For example - loaded by default with MS DSS80 Speakers because they have Volume, Mute and Bass controls on the speaker. Some users may experience problems disabling this - if this is the case then re-enable it. Equivalent to MMHid in Win98. On HP Computers, HIDSERV is the controller for the keyboard sound controls on the USB and PS/2 keyboards
    Xhid_startgzmrotate.dllAdRotator/IconAds adware
    NHigh Definition Audio Property Page ShortcutHDAudPropShortcut.exeRealtek audio card related - probably adds the odd feature to one of the "Sounds" Control Panel applet tabs - doesn't appear to be required
    NHigh Definition Audio Property Page ShortcutHDAShCut.exeHigh definition audio page shortcut for Realtek audio devices - not required
    UHigh Definition Audio Property Page ShortcutCHDAudPropShortcut.exeRealtek high definition audio related
    YHighPoint ATA RAID Management Softwareraidman.exeHighPoint RAID management - hard disk striping/mirroring utility for increased performance and reliability. See here for more information on RAID
    XHighspeeddownloaderSetupClickHere.EXEHomepage hijacker, redirecting to "turbo-search101.com" - see here
    UHijackThis startup scanHijackThis.exeHijackThis lists the contents of key areas of the Registry and hard drive areas that are used by both legitimate programmers and hijackers. The program is continually updated to detect and remove new hijacks. It does not target specific programs and URLs, only the methods used by hijackers to force you onto their sites. As a result, false positives are imminent, and unless you're sure about what you're doing, you always should consult with knowledgable folks before deleting anything. Required if you'd like HijackThis to run a scan at startup, and show the results when new items are found (if so, check the appropriate box in the "Config" section")
    XHijSrv32hijsrv.exeAdded by the BANKGERM-D TROJAN!
    Xhimem.exe[path to worm]Added by the STRATION-FW WORM!
    XHistoriaLout.GDC.exeAdded by and unidentified misleading security program
    NHistoryKillhistkill.exeHistoryKill removes your web surfing path by removing the URL drop-list history, detailed history file, cache, and cookies in both IE and Netscape Navigator browsers. Available via Start -> Programs
    UHitman Pro SurfRight Helpersrhelper.exeHitman Pro - a utility to start a number of Security Protection software. They can be started individualy
    XHitQHitQ.exeHijacker, for more information see here
    UHitwarePKLiteHITWAR~1.EXEHitware Popup Killer Lite
    XHIVHIV.exeAdded by the HIVA TROJAN!
    Uhkhk.exeKeyLoggerExp keystroke logger/monitoring program - remove unless you installed it yourself!
    Uhkcmdhkcmd.exePart of Intels Common User Interface for chipsets with integrated graphics controllers - which allows user to change different driver properties through Windows User Interface. If the user wishes to have "HotKey" access to Intel's customised graphics properties, it is required, otherwise not. It can be disabled via the Display Properties in the Control Panel
    XHKEYokrunlli32.exeAdded by the QQPASS-U TROJAN!
    XHKLM\Runwindowsupdate.exeAdded by the FORBOT-BJ WORM! (where HKLMRun represents HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun)
    UhkservHKserv.exeKeyboard manager program required to use programmable power and function keys on some laptops such as the Sony PCG R505TS
    Uhksshkss.exeCompaq HotKey Support - multimedia keyboard support
    XHLcleanuphlsetup2.exeLinkReplacer/FFinder adware
    Xhldrrrhldrrr.exeAdded by the BAGLE-KF WORM!
    Xhlhtxo.exehlhtxo.exeAdded by the QLOWZONES-27 TROJAN!
    XHLL Data Parameterhllcxpa.exeAdded by the RBOT.AFG WORM!
    XHMI PowerSystemhmisvc32.exeAdded by the RANDEX.CZZ WORM!
    XHML PowerSourcehmlsvc32.exeAdded by the SDBOT-XL WORM!
    UHmonitorHmonitor.exeHardware sensor monitoring program. Only required if you overclock your system and want to check on the status
    XHMV PowerSourcehmusvc32.exeAdded by the SDBOT-YW WORM!
    Xho2stdll.exeho2stdll.exeAdded by the BANKER-HO TROJAN!
    XHOI Servicesholsvc32.exeAdded by the AGOBOT-SF WORM!
    NHoliday LightsHoliday Lights.exeHoliday Lights from Tiger Technologies. Festive desktop enhancement that adds lights. Available via Start -> Programs
    XHollabackslvhosts.exeAdded by the SDBOT.BMO WORM!
    NHome Theater SchSvrSchSvr.exeWinScheduler is installed with Home Theater Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs
    UHomeAlarmHomeAlarm.exeChameleon Clock - system tray clock replacement
    ?HomeCentre WakeUpLGWAKEUP.EXEAssociated with the no longer supported Xerox HomeCentre printer/scanner
    XHomeland NetworkHomelandNetwork.exeHomeland Network Notifier - pops ads
    Xhomepage.monitor.exeisamonitor.exeAdded by the ZLOB-QK TROJAN!
    UHondaHelperHondaHelper.exePart of Honda Music Link which allows you to use your Honda's audio system's controls to play and search for music on your iPod? in you car
    ?Honorhonor.exe??
    UHook99startuphk2re.exe"Hook99 enables the user to customize the start button. You can change or remove the text and replace the Windows flag on button with icon of your choice. Supports Windows icons, bitmaps and can extract icons from executables and libraries. Hook99 can also make the background of desktop icons captions transparent"
    UHookSysHookSys.exeSurfinGuard Pro from Finjan - internet protection software, protects against all malicious code delivered through executables, scripting files, ActiveX and Java
    UHornetMonitorMntrHrnt.exeHornet Monitor - monitoring system that detects and responds to unauthorized access attempts and sources of channel interference on any local DSSS network
    YHorngTech4Dbally4d.exeHorngTech 4D mouse driver
    XHostN/AAdded by the POPDIS or STARTPAGE.F TROJANS!
    Xhosthelp.exeIdentified as the DELF.LF by Ewido Security Suite
    XHost Processmame.exeAdded by the RBOT-APO WORM!
    XHost Processsvchost.exeDetected by Kaspersky as the AGENT.DGO TROJAN! See here. Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! The file is located in the Fonts directory
    Xhostdll.exehostdll.exeAdded by the BANKER-BO TROJAN!
    UHostManagerAOLHostManager.exeManages a component essential to the operation of most current AOL software. If you remove it from startup it will load when IE is launched, increasing launching time
    NHostManagerAOLSoftware.exeQuoted from AOL Beta Team, "Manages a component essential to the operation of most current AOL software, client or not. You should be able to remove it from Startup (it'll just load when Explorer is launched, which will extend load time a bit), but do leave it on your system".
    XHostname Manager Serverhost32srv.exeAdded by a variant of the RBOT WORM!
    XHostren.exeHostren.exeAdded by PWS.BANKER.F, a variant of the BANKER-BO TROJAN!
    Xhostservhostserv.exeAdded by the RBOT.BPZ WORM!
    Xhostservwiz98.exeAdded by a variant of the SDBOT WORM!
    UHostsFileMgrwinHostsEdit.exeAdBin from Gilmore Software Development. An easy solution to managing your Window's hosts file
    UHostsManhm.exe"HostsMan is a freeware application that lets you manage your Hosts file with ease". It is mainly intended to block specific domains (mostly advertising servers) by redirecting them to localhost, but can also be used to add any other domain/Ip combination that you want to be included in the HOSTS file
    XHostSrvsachostx.exeAdded by the LOOKSKY.H WORM! Drops multiple files in the System (9x/ME) or System32 (NT/2K/XP) folders
    XHostSrvsachostx.exeAdded by the LOOKSKY.A or LOOKSKY.F or LOOKSKY.G WORMS!
    XHostSrvsachostx.exe...Added by the LOOKSKY.E WORM!
    XHostSVC syseHostSVC.exeAdded by the RBOT-ANZ WORM!
    UHot CornersHotc.exeHot Corners - "lets you quickly activate or disable your screen saver by moving the mouse into a given corner of the screen"
    XHOT FIXGothic.exeDetected by Kaspersky as the RBOT.ESX WORM!
    XHot InsideHottest Story Ever.exeAdded by the BHARAT.A WORM!
    UHot Key Kbd 2690 DaemonSK9910DM.exeMultimedia keyboard manager - required if you use any special keys
    UHot Key Keybd 9910 DaemonSK9910DM.exeMultimedia keyboard manager - required if you use any special keys
    ?Hot Party 22hotpart22.exe??
    XHotAction_hrhotaction_hr.exeAdded by the SITEICON-B DIALER! An uninstall option can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as "HotAction_hr"
    XHotbarHbinst.exeHotbar adware
    XHotbarHbOEAddOn.exeHotbar adware
    XHotbarOEOEAddOn.exeHotbar adware
    XHotbarSAHotbarSA.exeHotbar adware
    Xhotdlllremote.cmdAdded by the BANKER-EHG TROJAN!
    Xhotfixmsnnmaneger.exeAdded by the WOOTBOT.AF WORM!
    XHotfix Updatsvdhost32.exeAdded by the GAOBOT.ZW WORM!
    UHOTFOON2hotfoon4.exeRelated to Hotfoon - a developer and provider of Internet Telephony technology based on LTP (Lightweight Telephony Protocol)
    UHotIDEhotide.exeHotIDE allows Acer TravelMate owners to hot-swap external drives without switching of their notebooks
    UHotkeyAppHotkeyApp.exeProgrammable keys on Acer, Fujitsu and other laptops
    UHotKeysCmdshkcmd.exePart of Intels Common User Interface for chipsets with integrated graphics controllers - which allows user to change different driver properties through Windows User Interface. If the user wishes to have "HotKey" access to Intel's customised graphics properties, it is required, otherwise not. It can be disabled via the Display Properties in the Control Panel
    XHotKeysCmds[path to worm]Added by the PAHATIA-A WORM!
    XHotPixhotpix.exeAdult content dialler
    Xhotplughotplug.exeAdded by the SILLYDL TROJAN!
    UHotplughot_plug.exeRelated to the SiS_Hot_Plug_Application. Enables automated driver loading for hotpluggable devices. If this service is stopped, hotplug devices will no longer function
    NHotSync Managerhotsync.exeInstalled when connecting a Palm HotSync cradle up to a USB port. The Blue and Red Arrow Icon that enables Palm / Handspring Synchronizing.  Available via Start -> Programs
    Xhotwetlovehotwetlove.exeAdult content dialler. Will not uninstall - components have to be manually deleted
    XHot_KissHot_Kiss.exeAdult content dialler
    XHot_TartsHot_Tarts.exeAdult content dialler
    XHot_Tarts_**Hot_Tarts_**.exePremium rate adult content dialer (where * is a random char)
    XHot_Tarts_AuHot_Tarts_Au.exePremium rate adult content dialler
    XHot_Tarts_mcHot_Tarts_mc.exeHotTarts adult content dialer
    UHoverDeskHoverDesk.exeHoverDesk - desktop replacement software
    ?hp 1000 firmwarefwdl.exeHP LaserJet 1000 related. Is it a driver or automatic firmware update (based upon the filename)?
    UHP AutoIndexerhppautoindexer.exeInstalled by HP multi-function printer driver software, related to PC faxing. If you are not using the PC faxing feature you can go ahead and disable these services from the startup
    NHP CD Writerhpcdtray.exeSystem Tray access to a HP CD-Writer's functions. Available via Start -> Programs
    NHP CD-DVDhpcdtray.exeSystem Tray access to a HP CD-Writer's functions. Available via Start -> Programs
    NHP CD-Writerhpcdtray.exeSystem Tray access to a HP CD-Writer's functions. Available via Start -> Programs
    Xhp centerBACKWEB-*****.exeSee here - "messaging service that automatically sends you support information, tips, ideas, and special offers from HP and our partners, especially designed for HP and Compaq desktop computer owners". Applies to certain HP Pavilion desktop computers between Fall 2001 and Spring 2003. * can be any digit
    Nhp center UIShadowBar.exeUser Interface for HP Center - see here
    NHP Component Managerhpcmpmgr.exeChecks the internet for updated drivers/utilities for your HP product - update manually. Disabling will remove the error "Windows can't shutdown the computer because hpcmpmgr.exe can't be ended"
    XHP DeskjetHP_DeskJet_500.exeAdded by the FORBOT-DA WORM!
    UHP Digital Imaging Monitorhpqtra08.exeSystem Tray access to HP Director. Required if you prefer to use the all-in-one buttons to manually scan documents or transfer photos froma camera, for example
    UHP Display Settingshpdisply.exeSets default display settings. Unchecking this item has been reported to cure a "Problem sending command to keyboard" error message
    UHP Health Check ScheduleHPHC_Scheduler.exeHP Health Check Scheduler from Hewlett-Packard
    ?HP IDSchedulerHPIDSCHD.exeHP Instant Delivery Scheduler
    NHP Image Zone Fast Starthpqthb08.exeImproves the startup time of HP Image Zone. If you disable it, HP Image Zone takes a long time to start up only the first time you run it. Subsequent startups are much faster than the first time
    NHP Info Express??On HP PCs, allows the computer to automatically receive notifications from HP over the Internet. Associated with BackWeb
    UHP Instant Supportmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". HP Instant Support is required to run with the Help and Support program. If you uncheck HP Instant Support and and then run Help and Support it will add another HP Instant Support in the startup menu. If you remove the HP Instant Support in the add/remove program some help menus in help and support will not be available. You decide
    NHP Internet CenterSURFBRD.EXELoads the HP Internet center surfboard on startup. HP Internet Center allows you to customize the multimedia keys on the fly without having to go the Control Panel --> Keyboards to change them
    NHP JetDiscoveryHPJETDSC.EXEHP JetAdmin software which monitors printing jobs on a network environment
    NHP JetSpeed AutostartAUTOSTART.EXEAutostart executable for the old multiplayer game HP Jetspeed
    UHP Laser Jet Directorhppdirector.exeSystem Tray icon that opens various functions such as copy, fax, email, scan, copy plus, etc. Right-click on it and you see a few options such as the preceding bar plus About, Help, ToolBox, Exit, etc
    ?HP Network Registry Agenthpnra.exe??
    ?HP OfficeJet Series xxx StartupHPOSTR03.EXExxx represents the series number - such as 700. What does it do and it it required?
    ?HP OfficeJet Series xxx StartupHPOstr05.exexxx represents the series number - such as 700. What does it do and it it required?
    NHP Parallel Port Testhppt.exeAssociated with a HP ScanJet scanner
    XHP Photo ManagerHPPhotoManager.exeAdded by the SDBOT.AXU WORM!
    ?HP Port Resolverhpbpro.exe??
    NHP Precision Scanhpmdlbwx.exeHP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
    NHP Presentation ReadyPresRdy.exeHP Omnibook related:  "Press a dedicated button above the keyboard and the system will instantly load your presentation software and change the screen resolution to match your display device"
    Uhp psc 2000 Serieshpobnz08.exeSystem Tray icon indicating when the printer is ready. Can be started manually with HP Director but takes time to start
    UHP RecordNow??From HP "Software for the CD writer. Do not prevent from starting unless the CD writer is never going to be used."
    UHP ScanPatchHPScanFix.exeProgram that starts up and automatically fixes earlier versions of the Scanjet 5100c software. If a Scanjet 5100C scanner is not going to be used, then it is safe to remove or prevent from starting
    NHP ScanPicturehpsplmwa.exeHP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
    UHP SchedIndexerhppschedindexer.exeInstalled by HP multi-function printer driver software, related to PC faxing. If you are not using the PC faxing feature you can go ahead and disable these services from the startup
    XHP Service Drivershdsys.exeAdded by the SDBOT-ZE WORM!
    ?hp Silent ServiceHpSrvUI.exeHP related
    NHP Simple TraxHpcron.exeSupplied with HP CD-RW drives - stores information about CD contents on your hard drive. Available via Start -> Programs or Desktop Icon
    NHP software updateHPWuSchd2.exeHP software updates. If a shortcut doesn't exist create your own and run it manually
    NHP software updateHPWuSchd.exeHP software updates. If a shortcut doesn't exist, create your own and run it manually
    NHP Statushpstatus.exeHP Printer Status and Alerts
    ?HP Status Serverhpboid.exeCopied during installation of HP Inkjet Printer Drivers in Win2K/XP. What does it do and is it required?
    UHP TV NowHpTvNow.exeApplication supplied with HP notebooks. It activates the S-Video port and is said to improve the quality of the output signal (resolution/timeouts)
    XHP Update AssistantHPAware.exeAdded by the MRO TROJAN!
    NHP Updates??On HP PCs, allows the computer to automatically receive notifications from HP over the Internet. Associated with BackWeb
    ?HP Visualize InitHpVisIni.exeHP Visualize software related. What does it do and is it required?
    NHP-Aio FlightRemind32.exeHP multifunction registration
    UHPADVISORHPAdvisor.exeHP Total Care Advisor - a suite of help and hardware check programs to help you check the health of your PCs
    Nhpaiodevicehpodev07.exeDirect from HP - "Device Objects Server - detects all device events and handles all ongoing communication on the device. Loads in the Startup group (except when "portable" is chosen during installation)". Related to various HP all-in-one printer/scanner/copier devices. They print and copy fine with those files disabled, and the icon installed on the desktop that points to "hpodir07.exe" works just fine if you need to use the scanner
    ?HPAiODevice(hp officejet g series)hpoavn07.exeHP Printer related, reportedly lets file transfers from an HP device pass files through Windows firewall. Is it required?
    NHPAiODevice(hp psc 900 series) -1hpobrt07.exeInstalled with a Hewlett Packard 900 series colour printer, scanner, fax, photo card slot printer, copier. Assumed to perform an identical function to the hpaiodevice entry
    NHPAIO_PrintFolderMgrhpoopm07.exeDirectly from HP: "This process has one purpose - detects if the device moves to a different port, and notifies other processes to look on the new port." For various HP all-in-one printer/scanner/copier devices. They print and copy fine with those files disabled, and the HP icon installed on the desktop that points to "hpodir07.exe" works just fine if you need to use the scanner
    UHPBootOpHPBootOp.exe"HP Boot Optimizer intelligently and dynamically launches software during startup, based on available resources, to improve startup performance"
    Xhpcmdcmd.exeAdded by the ADCLICK-DS TROJAN!
    Nhpcmpmgrhpcmpmgr.exeChecks the internet for updated drivers/utilities for your HP product - update manually. Disabling will remove the error "Windows can't shutdown the computer because hpcmpmgr.exe can't be ended"
    UHPDJ Taskbar Utilityhpztsb01.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
    UHPDJ Taskbar Utilityhpztsb02.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
    UHPDJ Taskbar Utilityhpztsb04.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
    UHPDJ Taskbar Utilityhpztsb05.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
    UHPDJ Taskbar Utilityhpztsb07.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
    UHPDJ Taskbar Utilityhpztsb09.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
    UHPDJ Taskbar Utilityhpztsb06.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
    UHPDJ Taskbar Utilityhpztsb08.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
    UHPDJ Taskbar Utilityhpztsb03.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
    UHPDJ Taskbar Utilityhpztsb10.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
    UHPDJ Taskbar Utilityhpztsb11.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
    UHPDJ Taskbar Utilityhpztsb12.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
    UHPDJ Taskbar Utilityhpztsb13.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
    Nhpfschedhpfsched.exeHPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature
    UHPGamesActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
    Nhpgs2wndhpgs2wnd.exe"HP's exclusive Share-to-Web software makes it easy to share content with others through our affiliate Internet websites". Available via Start -> Programs
    UHpha1monHpha1mon.exeSupports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 2.0 to 2.3 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature
    UHpha2monHpha2mon.exeSupports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 2.0 to 2.3 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature
    UHpha3monHpha3mon.exeSupports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 2.0 to 2.3 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature
    UHPHmon**HPHMON**.EXEMonitors the status of the memory card reader slot on a HP printers and displays a tray icon if a memory card isn't inserted. Also creates a virtual drive and assigns it the first available drive letter - which can lead to problems with drive management. ** represents the version number. Disable if you don't use the reader
    UHPHmon03hphmon03.exeSupports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 2.0 to 2.3 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature
    UHPHmon04hphmon04.exeSupports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 2.0 to 2.3 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature
    Uhphmon05hphmon05.exeSupports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 2.0 to 2.3 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature
    UHPHmon06hphmon06.exeSupports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 2.0 to 2.3 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature
    XHphomehphome.jsHomepage hijacker
    NHPHUPD04hphupd04.exeHP software update checker and wizard launcher. Available via Start -> Programs
    NHPHUPD05hphupd05.exeHP software update checker and wizard launcher. Available via Start -> Programs
    UHPHUPD06hphupd06.exeHP software update checker and wizard launcher. Available via Start -> Programs
    NHPHUPD07hphupd07.exeHP software update checker and wizard launcher. Available via Start -> Programs
    NHPHUPD08hphupd08.exeHP software update checker and wizard launcher. Available via Start -> Programs
    ?hpjsiroutehpjsira.exeRelated to HP laserjet printers and IP addresses. An IP address is appended to the name field - ie "hpjsiroute192.168.1.2"
    XHPl Serviceshmlsvc32.exeAdded by the AGOBOT-SI WORM and variants!
    YHpLampHPLAMP.EXEHP Scanner Utility that controls your scanners light bulb. Needed if it's switched on
    Uhplampchplampc.exeHP Scanner Lamp Utility - fixes an issue with the scanner lamp not going off
    UHPLaptopGamesActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
    YHPLJ ConfigSetConfig.exeConnects system to networked HP printer.
    UHPLogiFinderhp_finder.exeHP LogiFinder helps detect and allows the use of the centre button for the Logitech mouse. Can be disabled if not used
    UHpMmKbdHpMmKbd.exeHP's multimedia keyboard driver which enables the end-user to use the automation features of the HP multimedia keyboard
    UHPMVTrayHPMVTray.exeHP Media Vault Networked Storage Device - System Tray management utility
    XHPNThpdll.exeMalware downloader - detected by Kaspersky as the VB.KU TROJAN!
    Nhpodbliahpodblia.exeHP OfficeJet Scan Button Monitor on a multi-function printer/copier/scanner. Start your scanning software manually
    Nhpoddt01.exeN/AInstalled by the "HP Photo and Imaging Director" software. If you ask for the imaging software, this program will be started
    Nhpodlb08hpodlb08.exeHP OfficeJet Scan Button Monitor on a multi-function printer/copier/scanner. Start your scanning software manually
    Yhpotdd01.exehpotdd01.exeDetection of new imaging, printing and other peripherals on HP machines such as USB printers, cameras and Bluetooth products. "This program is a non-essential process, but should not be terminated unless suspected to be causing problems"
    Yhpppthpppt.exeRelated to the drivers for HP ScanJet scanners
    YhppptaHPPPTA.exeHP parallel port driver for certain hardware
    XHpPrinterhpserver.exeAdded by the CMJSPY-W TROJAN!
    NHPPROPTYHPPROPTY.EXEHP LaserJet Toolbox
    UHPPWRSAVHPPWRSAV.EXEPower save related for HP Scanners. Many users have complained of system freezes with it running but it stops the light from remaining on all the time. Try www.hp.com, pick your OS option under the SUPPORT tab, follow the instructions and you will find an updated lamp control patch
    ?hpqcmonhpqcmon.exeFrom HP and related to digital imaging
    UHPSCANMonitorhpsjvxd.exeHP scanning software that enables you to scan images from your scanner. Needed if you're using the scanner
    ?hpScannerFirstBootscannerfb.exeHP scanner related
    Nhpsjbmgrhpsjbmgr.exeHP ScanJet Button Manager. It allows users of the HPScanJet scanners to indicate what the buttons on the scanner will do automatically if pushed. Not required at startup, unless the scanner is used every day, such as in a business environment
    NHPStarthpstart.wsfThis a script used by HP that runs the first time one of their computers is started. Can't imagine why it would be starting up after the first boot
    Xhpsysconf1[random filename]Added by a variant of the VIVIA.A TROJAN!
    Uhpsysdrvhpsysdrv.exeThis item keeps track of how many times the system has been recovered and the times of the first and last recoveries done on the system. Leaving unchecked will sometimes prevent the Keyboard Manager program from detecting that the computer is an HP. Since this program/driver was only made to run on HP, if it can't tell that it is an HP it will not run. If unchecked, it can prevent the running of the Application Recovery CDs, the use of the multimedia keys, and the HP Instant Support. Also seen that without it running, the Riptide Sound card that was installed on some older HP computers stops working
    Xhptoolshptools.exeAdded by a variant of the SDBOT WORM!
    Xhptoolsmicrosoft.exeAdded by a variant of the SDBOT WORM!
    NHPUProvenTactics.exeProven Internet Marketing software
    UhpWirelessAssistantHP Wireless Assistant.exeThe HP Wireless Assistant is a user application that provides a way to control the enablement of individual wireless devices (such as Bluetooth or WLAN devices) and that shows the state of the radios for these wireless devices
    UhpWirelessAssistantHPWAMain.exeWireless application bundled with HP computers that allows you to control different settings on the computer's wireless devices such as Bluetooth and WLAN
    NHPZTS04hpzts04.exeHewlett Packard printer toolbox shortcut that resides in the system tray
    Uhpztsb02hpztsb02.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
    Uhpztsb04hpztsb04.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
    Uhpztsb05hpztsb05.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
    Uhpztsb07hpztsb07.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
    Uhpztsb09hpztsb09.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
    Uhpztsbolhpztsbol.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
    NHP_dladlatray.exeOn HP PCs, tray icon for dla - which provides drive letter access to HP's and Veritas' version of DirectCD
    XHQI Serviceshqisvc32.exeAdded by the AGOBOT-RO WORM!
    XHQI Serviceshqlsvc32.exeAdded by the AGOBOT-RP WORM!
    UHRHr.exeHiddenRecorder periodically takes screenshots of the computer. If you didn't install this yourself remove it
    UHREF.OCXregsvr32.exe ....HREF.OCXHREF.OCX is an ActiveX control developed by xFX JumpStart and used to provide HTML-alike clickable links on Windows-based programs such as PopUpKiller
    XHrn_qtvhrnsvc32.exeAdded by the SDBOT-AET WORM!
    Xhsimisearch.exeUnidentified malware
    Xhsimsexgame.exeUnidentified malware
    Xhsimtoolbar.exeUnidentified malware
    UHSLAB Loggerlogger.exeHSLABLogger logs user activity and Internet activity. The gathered information can be sent to a predetermined email address. If you didn't install this yourself uninstall it
    UHSONHSON.exeToshiba HotStart button support for instant-on entertainment on their laptops
    UHSTranshstrans.exeHomescan Internet Transporter - part of ACNielson Homescan. Recognizes when the ACNielsen Homescan Scanner is attached to the computer and allows it to transmit scanner information to ACNielsen
    ?HsuGuiControlHsuGuiControl.exePart of the Starband Internet satellite client. What does it do and is it required?
    UHtinpdor.exeAppears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required
    XHTML Help Systemhhs.pifAdded by the RBOT-ATB WORM!
    XHTML32 Help Systemhhs32.pifAdded by the RBOT-ATE WORM!
    UHTpatchhtpatch.exeHTpatch.exe is part of the SiS AGP patch - BUT unless your processor (and motherboard) supports HyperThreading (HT) and this feature is enabled it will actually SLOW your graphics card by around 6%
    XHtProtectAVprotect.exeAdded by the NETSKY.L WORM!
    Xhtssv32.exehtssv32.exeAdded by a variant of the SDBOT TROJAN!
    XHTTP Tunneling Servermstunnel.exeAdded by the RBOT.EDL WORM!
    Xhttp://www.lienvandekelder.beLienVandeKelder.exeAdded by the MYTOB-AZ WORM!
    Xhttp://www.lienvandekelder.beLien Van de Kelder.exeAdded by the MYTOB-AP WORM and variants!
    Xhttp://www.lienvandekelder.beLien Vande Kelder.exeAdded by the MYTOB-AQ WORM!
    Xhttp://www.lienvandekelder.beLien vd Kelder.exeAdded by the MYTOB-M WORM!
    Xhttp://www.lienvandekelder.beLien.exeAdded by the MYTOB-CZ WORM!
    Xhttp://www.lienvandekelder.beLientjeuh.exeAdded by the MYTOB-P WORM!
    Xhttp://www.lienvandekelder.beLienVdK.exeAdded by the MYTOB-U WORM!
    Xhttp://www.lienvandekelder.beVan de Kelder Lien.exeAdded by the MYTOB-BF WORM!
    Xhttp://www.lienvandekelder.beWe Love Lien Van de Kelder.exeAdded by the MYTOB-CV WORM!
    Xhttp://www.lienvandekelder.comLien Van de Kelder.exeAdded by the MYTOB-EQ WORM!
    Xhttp://www.lienvandekelder.com/LienVandeKelder.exeAdded by the MYTOB-EO WORM!
    Xhttpdc_pan.exeAdded by a variant of the DELF-A TROJAN!
    Xhttpddeamon.exeAdded by the TACTSLAY.C TROJAN!
    Xhttpdmsgaol.exeAdded by the TACTSLAY.C TROJAN!
    Xhttpds_menu.exeAdded by the TACTSLAY.C TROJAN!
    Xhttpdbrowse.exeAdded by the TACTSLAY.C TROJAN!
    Xhttpddeamon.exeAdded by the TACTSLAY.C TROJAN!
    Xhttps-sslhttps.exeAdded by the MOEGA.D WORM!
    UHughesNet Toolsmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". HughesNet Help is required to run with the Help and Support program. If you uncheck HughesNet Help and and then run Help and Support it will add another HughesNet Help in the startup menu. If you remove the HughesNet Help in the add/remove program some help menus in help and support will not be available. You decide
    ?huhdirhuhdir.exe??
    XhuigeziHgzServer.exeAdded by the GRAYBIRD.C TROJAN!
    XHvewsveqmgANACON.EXEAdded by the NACO.A WORM!
    XHvidHvid.exeAdded by the GEMA TROJAN!
    XHWINFO*HWINFO*Added by the PUROL WORM! where * is a random character
    YHWinstN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
    XHwpsystem_wc.exeEziin adware
    Xhwshws.exeAdded by the STARTPA-CT TROJAN!
    UHWSetupHWSetup.exe hwSetUP"Toshiba Hardware Setup is the Toshiba configuration management tool available through Windows." Allows the user to change BIOS, hard disk, memory, boot disk priority and other settings
    Xhxadsec[path to trojan]Added by the ADCLICK-AP TROJAN!
    XHXDL.EXEHXDL.EXEAttune HelpExpress - spyware. Disable and uninstall - see here
    XHXIUL.EXEHXIUL.EXEAttune HelpExpress - spyware. Disable and uninstall - see here
    UHydarVisionDesktopManagerdesk95.exeATI's HydraVision desktop management software, allowing for multi-monitor support, as included in ATI HydraVision versions 2.5 and earlier. Has been reported to cause problems, such as this one. HydraVision can be uninstalled through Add/Remove Programs
    UHydraVisionDesktopManagerdesk98.exeATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
    UHydraVisionDesktopManagerHydraDM.exeATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
    UHydraVisionViewportviewport.exeATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
    XHyper Startinstantmsgrs.exeAdded by the RBOT-NH WORM!
    XI am not Ranky. I am eTunnel!msyervice.exeAdded by an unidentified WORM or TROJAN!
    XI am not Ranky. I am eTunnel!winsys.exeAdded by an unidentified WORM or TROJAN!
    XI am not Ranky. I am eTunnel!disney.exeAdded by an unidentified WORM or TROJAN!
    XI just want to say I love Milko and I need a drinksvchost.exeAdded by the CHIKO WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Documents and SettingsAdministratorLocal SettingsApplication Data folder
    XI-Worm.GiGuuGiG.eXeAdded by the GINK WORM!
    XI/O Controllerssvcnet.exeAdded by the TIBIK-B TROJAN!
    XI386I386.exeAdded by the MYPOWER WORM!
    ?I81SHELLI81SHELL.exeAppears to be related to drivers for an Intel 810 graphics chipset on an ASUS motherboard
    Ui8kfanguii8kfangui.exeGraphical interface for fan speed control
    UIAAnotifiaanotif.exeIAA Event Monitor User Notification Tool - part of Intel? Application Accelerator - "a performance software package for desktop PCs using select Intel? chipsets" that "replaces the ATA drivers that come with Windows with drivers optimized for desktop and mobile PCs." If you use the RAID version it's required to notify you if a RAID 1 disk has failed
    Yiamappiamapp.exeAtGuard personal firewall engine. As Atguard was bought by Symantec some time ago, it's now the Norton Personal Firewall executable as well
    XIamnacho On Irc.MusIrc.com Is a Homosexual!XBox64.exeAdded by the RANDEX.Y WORM!
    ?Iapiap.exePossibly part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely?
    Uiasias.exeInvisibleASpy keystroke logger/monitoring program - remove unless you installed it yourself!
    XIASHLPRIASHLPR.EXEAdded by the OPASERV.T WORM!
    Xibin[path to trojan]Added by the PERDA-C TROJAN!
    Xibmibm.exeAdded by the LEGMIR-AH TROJAN!
    XIBM Keyboard Driverikeybdrv.exeAdded by the SDBOT.IC TROJAN!
    ?IBM Warranty NotificationERTS0749.exeIBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?
    Nibmmessagesibmmessages.exeAllows IBM to push messages onto users' computers. Quote: "The Access IBM Message Center can display messages to inform you about software and solutions available from IBM as well as messages from IBM eSupport"
    ?Ibmmon.exeIbmmon.exe??
    UIbmpmsvcibmpmsvc.exePower management driver for IBM laptops. Provides support for the use of four keys on the thinkpad keyboard with blue key tops - Fn, F3, F4 & F12 - which have specific functions to control the standby and hibernate buttons. Not required if you don't plan to go into standy or hibernate modes
    ?IBMPRCibmprc.exeIBM application - what does it do and is it required?
    UIBMUltraBayHotSwapCPLLoaderIBMBAY2N.EXESupports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops
    ?IBMUltraBayHotSwapSoundIBMBAYSN.EXESupports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops. Is it needed though - does it just play a sound?
    YIBM_PWMGRpwmgr.exeIBM Password Manager
    XIbsibs.exeAdded by the HIDEDIAL-B TROJAN!
    UIBWin Background processIBackground.exeIBackup for Windows
    UIBWin MonitorIBMonitor.exeIBackup for Windows
    YIcaBaricabar.exeRelated to Citrix MetaFrame
    XicasServicasServ.exeBrowser hijacker, redirecting to Searchforfree.info. Also detected as the ICASERV-A TROJAN!
    XICcontroliccontrol.exeAdded by the ICcontrol premium rate adult content dialer
    Xicdd7ee6rundll32.exe icdd7ee6.dll, EnableRunDLL32LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "icdd7ee6.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    Xicddefffrundll32.exe icddefff.dll, EnableRunDLL32LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "icddefff.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    NICH Syntheusexe.exeSound related and can be disabled without affecting performance although advanced sound features may be sacrificed. May be related to Compaq PC's with "SoundMAX integrated Digital Audio" (Analog Devices Inc.) devices
    Xicifatiyujixit.exeAdded by the SDBOT.ZZH WORM!
    UiCleaniClean.exeIEClean - "advanced, comprehensive package of tools which perform a number of functions to allow you to control your online privacy"
    UICMICM.EXEStarts Internet Call Manager dialog box and/or taskbar icons at bootup. This is a subscription program from internetcallmanager.com that monitors a dialup phone line for incoming calls and handles voicemail
    NiCnNAG.EXEiChoose - shopping browser enhancement that alerts you to cheaper deals for goods you want to buy, if they exist. Not related to the Mac icon program of the same name
    UICOICO.EXEFound on some Sony Vaio, IBM Thinkpad and Dell (and possibly other) laptops and seems to be related to Mouse Suite 98 Daemon according to the properties. Required on the Dell Inspirion 530 as without it the Dell mouse suite does not load and mouse settings are not retained on a reboot. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games
    NIcon AnimationHDE.EXEPart of McAfee Nuts & Bolts. Provides entertaining animation of your desktop icons
    NIcon Hearit 95hearit95.exeAudio desktop customization utility from Moon Valley Software. Resource hog
    NIcon Hearit 98hearit98.exeAudio desktop customization utility from Moon Valley Software. Resource hog
    XIcon lptt01icon.exeRapidBlaster variant (in a "Icon" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
    XIcon ml097eicon.exeRapidBlaster variant (in a "Icon" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
    Yiconcacheicon.batRelated to the Vista Customization Pack
    YICONCLNTiconclnt.exeAPC PowerChute Tray Icon. Associated with the UPS listing
    UICONDESKICONDESK.EXESmall utility which will allow you the option of hiding or showing your desktop icons
    NIconfig.exeIconfig.exeIcon for LS-120 "Superdisk"
    XiConfigLoaderDIIhost.exeAdded by the GAOBOT.AO WORM!
    NIconoidIconoid.exeIconoid is a desktop icon manager
    NIconsaverIconsaver.exeIconSaver is a desktop icon manager
    XICQICQNET.vbsAdded by the GORMLEZ-A WORM!
    XICQ Agenticq6.exeAdded by the AGENT-FZJ TROJAN!
    XICQ Center[path to worm]Added by the RANDIN WORM!
    XICQ Chat Serviceicqjdhs.exeAdded by a variant of the RBOT WORM!
    XICQ Hacking ProICQpro.exeAdded by a variant of the NETSPY TROJAN!
    NICQ LiteICQLite.exeICQ Lite - compact version of the popular messaging program
    Xicq litescvhost.exeAdded by the AGENT-DSF TROJAN!
    Xicq litewinlog.exeAdded by the IRCBOT-TJ TROJAN!
    XICQ Lite Messenger[random filename]Added by an unidentified VIRUS, WORM or TROJAN! Unlike the legitimate ICQ Lite executable, which will be located in the ICQLITE folder in Program Files, this particular impostor is located in the Windows or WinntSystem32 directory
    XICQ Messenger 2002ICQ2002.exeAdded by the SDBOT-ABL WORM!
    XICQ Netwinlogon.exeAdded by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!
    NICQ Plusvplus.exeICQ Plus is a freeware utility makes your ICQ skinnable (change the look). Available via Start -> Programs
    XIcqBetawebcamupdate.exeAdded by an unidentified TROJAN!
    XICQNetwinlogon.exeAdded by the NETSKY-C WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
    Xicrosof Avps32 Controlav32.pifAdded by the RBOT-AVC WORM!
    Xicrosoft Visualplscx.exeAdded by the RBOT-AYO WORM!
    Xicrosoft Visual InterDevczvslmqb.exeAdded by the RBOT-AYP WORM!
    Xicrosoft Windows DLL Services Configurationpoker3.exeAdded by the SDBOT-AER WORM!
    Xicrosoftf Avpx Controlavpx.exeAdded by the RBOT-AYN WORM!
    UICSDCLTrundll32.exe Icsdclt.dll, ICSClientInternet Connection Sharing allows more than one computer to simultaneously access the internet with a single connection. Also required when networking two machines
    NICServerIcserver.exeIntel Intercast viewer software. Gives access to selected internet pages which are broadcasted by several TV stations
    YICSMGRICSMGR.EXEMonitors DNS and DHCP requests for ICS (Internet Connection Sharing). Needed if you're sharing the internet on various computers
    XICU-SuckerService32.exeAdded by the ILLNOTIFIER.D TROJAN!
    NIC_KEY_3spvic.exeInstant Chess related
    NID CommanderIDCom.exeCaller ID utility for identifying incoming telephone numbers
    XID8525ID8525.exeAdded by the ID8525.A TROJAN!
    XID8525id85255.exeAdded by the ID8525.A TROJAN!
    ?IDAIDA.EXEHP related - in a Program FilesHewlett-PackardPC COE folder
    XIDEide.exeAdded by the ASSASIN.F TROJAN!
    XIDE LoaderIDElibr32.exeAdded by the XILON TROJAN! Related to the game "Diablo II"
    Xidecntlidecntl.exeAdded by a variant of the CRYPTER.C TROJAN!
    UiDesktopidesktop.exeImmersion TouchWare Desktop software for devices such as the Logitech iFeel Mouse
    NIDManIDMan.exeInternet Download Manager - download files faster, schedule and resume
    Xidmlssp[random filename]Added by a variant of the SLAPER TROJAN!
    XIDTemplatesIDTemplate.exeAdded by the BRONTOK-H WORM!
    NIDW Logging Toolidwlog.exeAdded with WinXP SP1. Usually only found in internal builds only to indicate the current build being used. Can cause slow network logon problems
    XIE configureexplorer.exeAdded by the LINEAGE-C TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!
    UIE DoctorIEDoctor.exeIE Doctor Toolbar - "IE Doctor can help you to Repair IE easily, protect IE and OE from all malicious changes. It can Repair the HomePage, context menu, IE toolbar button, startup items, Favorites, typed URLs and the entire Internet Options"
    XIE Java Updateiejava.exeAdded by the AGENT-HD TROJAN!
    XIE Menu Extension toolbarrundll32.exe [path] tbextn.dll DllShowTBTopconverting.com180Search "IEMenuExtension" toolbar. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
    UIE New Window Maximizeriemaximizer.exeIE New Window Maximizer - automatically maximize new Internet Explorer and Outlook Express windows
    XIE Runtimewini.exeAdded by the PICRATE.B WORM!
    XIE Runtimeswinis.exeAdded by the RBOT-ADZ TROJAN!
    XIE**.exe [* = random char]IE**.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
    XIE**32.exe [* = random char]IE**32.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
    XIE-Bariebar.exeDesktopMedia adware
    XIE6wkstmg.exeAdded by a variant of the SDBOT WORM!
    XIE6ssmss.exeAdded by the GAOBOT.DXO WORM!
    XIE6porn.pifAdded by the RBOT-ATF WORM!
    XIE6winsnt.exeAdded by the RBOT-GOV WORM!
    XIEACCESStemp532.exeAsdPlug premium rate adult content dialer variant
    XIEACCESSsurfya.exeIEAccess premium rate adult content dialer variant
    XIEAgent update checkiewatch.exeAdded by the BOMKA TROJAN!
    Niecheckiecheck.exeIntegrity checker for IconEdit2 icon editor. It serves for IconEdit2 internal tasks only and can be safely deleted from the system if you are running the latest version of IconEdit2
    XIECheckMSDTCs.exeAdded by the TIRBOT-D WORM!
    XIECheckxpssl.exeAdded by the TIRBOT-E WORM!
    XIECheckmssvp.exeAdded by the TIRBOT-G WORM!
    UIECleanAuxIeboot6.exeIEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc. Performs cleaning tasks at startup
    Xiedlliedll.exeHomepage hijacker, redirecting to coolwwwsearch.com
    XIEDriverIEDriver.exeInstalled as part of adware (Cydoor) based peer-to-peer file sharing software called URLBlaze
    XIEDriverxplore.exeIEDriver adware variant
    XIEDriverTD.exeIEDriver adware variant
    Xiedwa104iedwa104.exeAdded by the DLOADR-BBW TROJAN!
    XIEengineIEeng.exeSTARTPAG.AI hijacker
    XIEexplorer AUpdateIEexplore32.exeAdded by the RBOT-GRE WORM!
    XIEFeaturesIEFeatures.exeAdded by the POPMON.A TROJAN! - also known as PopMonster adware
    XIEFeaturesInternetfeatures.exeAdded by the POPMON.A TROJAN! - also known as PopMonster adware
    XIefxTrayIefxTray.exeAdded by the RILER-H TROJAN!
    Xieharv.exeieharv.exeAdded by the BANKER-HH TROJAN!
    XIehelpersyslaunch.exeOutwar adware downloader
    Xiel2cde8rundll32.exe iel2cde8.dll, EnableRunDLL32LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "iel2cde8.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    Xielcaaberundll32.exe ielcaabe.dll, EnableRunDLL32LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ielcaabe.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    XIELoader32iexplore32.exeAdded by the SPEX or SPEX.B WORMS!
    XIesarIesar.exeBrowser hijacker - redirecting to an adult web page
    XIesearch.exeIesearch.exeLookNSearch adware
    XIESetIExplorer.dllAdded by the PWS-BLUEDIT TROJAN!
    Xiesetupi.exeiesetupi.exeAdded by a variant of the RBOT WORM!
    Xiestartiexp1orer.exeAdded by the NEMOG.C TROJAN!
    Nietsrietsr.exeIEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc
    XieupdateMCP****.exe [**** = random char]Added by the ASOXY TROJAN!
    Xieupdatemcpdll32.exeAdware downloader trojan
    XIEXPL0RERIEXPL0RER.EXEAdded by the AGOBOT-QL WORM! Note the filename has a "0" rather than an upper case "o"
    Xiexpl0resiexpl0res.exeAdded by the RBOT.AEX WORM! Note - this malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot
    XIExploersvshosts.exeAdded by the IRCBOT.BT TROJAN!
    XIexploitIexploit.htmlAdded by the INKER.B WORM!
    XIexploreiexplore.exeAdded by the BOXER TROJAN! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    XIEXPLOREiexplore.exeAdded by the APHEXDOOR TROJAN! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
    XIExploreIEXPLORE.EXEAdded by the DLOADER-YZ TROJAN! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in a "Custom" subfolder
    XIExploreIEXPLORE.exeAdded by the DLOADR-AAM TROJAN! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the "Arquivos de programasInternet ExplorerCustom" folder
    XIEXPLOREIEXPLORE.EXEAdded by the BANKER-BWE TROJAN! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    XIexplore Servicesiexplore.exeAdded by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup!
    XIEXPLORE.EXE[path to trojan]Added by the BANCOS-CJ TROJAN!
    XIEXPLORE.EXEgoot.exeAdded by the BIFROSE-C TROJAN!
    XIExplorerIexplor32.exeAdded by the BDOOR-BY TROJAN!
    XIExplorerIExplorer.EXEAdded by the BANCOS-CH TROJAN!
    XIEXPLORERmsiecfg.exeAdded by the JU or BANCBAN-IP TROJANS!
    XIexplorerexplorer.exeAdded by the ZAPCHAS-AC TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System folder
    Xiexplorer lptt01iexplorer.exeRapidBlaster variant (in a "iexplorer" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
    Xiexplorer ml097eiexplorer.exeRapidBlaster variant (in a "iexplorer" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
    XIexplorer.exeIexplorer.exeAdded by the BANCBAN-EN TROJAN!
    XIExplorer32 Java ScriptingIExplore32b.exeAdded by the RBOT.ABO WORM!
    XIExplorer32c Java ScriptingIExplore32cb.exeAdded by the RBOT.ABN WORM!
    XIExplorer6 Java ScriptingIExplore326.exeAdded by a variant of the SDBOT WORM!
    XIExplorer7 Java ScriptingIExplore327.exeAdded by a variant of the SDBOT WORM!
    XIExplorerServiceWinSock.exeDetected by Kaspersky as the AGENT.KIU TROJAN! See here
    Xifpipf.exeAdded by the CLAGGER-AG TROJAN!
    Xifperx[random filename]Added by a variant of the SLAPER TROJAN!
    UIFSplash.exeIFSplash.exeI-FORCE driver for force feedback steering wheel
    Xigamatuekor.exeAdded by the SDBOT.AQ TROJAN!
    Xigamatuatecaca.exeAdded by the IRCBOT.R WORM!
    Uigfxtrayigfxtray.exePart of Intels Common User Interface for chipsets with integrated graphics controllers - which allows user to change different driver properties through Windows User Interface. Quick access to the control panel via a System Tray icon. Available via Start -> Settings -> Control Panel
    ?IglpbvIglpbv.exe??
    Nigndlm.exeDLM.exeIGN Download Manager has become a requirement for downloading files through FilePlanet.com. It is based on Internet Explorer and it installs through an ActiveX-plugin, hence Internet Explorer must be installed beforehand and downloads has to be initialized through that browser
    Xigsex2xigsex2x.exeNewDial premium rate adult content dialler
    ?iHP-100iHPDetect.exeDrive Letter Searcher, iRiver iHP-100 iHP and H Series player related - does it need to start with Windows every time?
    XiilcIILC.EXEHomepage hijacker
    XIinliptl.exePurityScan/Clickspring adware
    XIISADMINSsystems.exeAdded by the AGOBOT.U WORM!
    Xiisversiisvers.exeAdded by an unidentified TROJAN or adware
    Xiiuyvyuuzcx.exeAdded by the AGENT-EOF TROJAN!
    NiIWiperSystemwiper.exeSystem Wiper from iI Software - allows you to clear the history of your activites from you computer. Run manually on a regular basis
    YIJ75P2PSERVERIJ75P2PS.EXEPrinter utility which is required in order to make the printer work correctly
    YIKE Service 95IKEService.exeAssociated with PGP. The PGP Tray can be disabled, but without IKESERVICE you won't be able to de- or encrypt anything
    UiKeyWorksIKEYMAIN.EXEA4Tech wireless keyboard driver and utility
    UIKLrundll32.exe [path] IKL.dllIKL surveillance software. Uninstall this software unless you put it there yourself
    XiLLeGaLMplayer.exeAdded by the HOLAR.C (or GALIL) WORM! Note - this should not be comfused with Windows Media Player which has the same filename
    XiLLeGaL.exeMplayer.exeAdded by the HOLAR.C (or GALIL) WORM! Note - this should not be comfused with Windows Media Player which has the same filename
    ?ILO_Office_ManagerIntEdReg.exe /OFFMANIntense Educational Ltd - Language Office Software. Is it required?
    UiLyriciLyric.exeiLyric plugin for Winamp media player. Allows you to retrieve the lyrics for your songs with the press of a button
    NiM Start CenteriM_Tray.exeInstalled with the Sound Blaster Audigy range of soundcards. A radio tuner installed if the user chooses during installation. Available via Start -> Programs -> iM Networks -> iM Radio Tuner
    XImagerundll32 image.dll, InstallCoolWebSearch parasite variant
    YImage & RestoreIMAGE32.exePart of McAfee Nuts & Bolts. Image/Restore can recover from drives that have been accidentally formatted or completely erased, if Image was recently run
    NImage TransferSonyTray.exeSony Image Transfer software provides direct image transfer from your digital camera to a PC - can be started manually
    UImageDrive-{hex numbers}ImageDrive.exeNero ImageDrive from Ahead - virtual CD/DVD drive software
    UImagefoximagefox.exeImageFox 2.0 (formerly available from ACDSee) is an "add-on" graphics previewer for most Windows Open/Save As dialog boxes
    XImagemgt32Imagemgt32.exeAdded by the GEMA TROJAN!
    XImagePathtaskbarmngr.exeAdded by the SDBOT-XB WORM!
    UImageTunedthtml.exeDisplay Tune (aka Image Tune) from Portrait Displays, Inc. - "is the perfect software utility to initially set-up and adjust your display to achieve its optimum performance. All adjustments are made through a simple graphical user interface and the user is guided, step-by-step, through the entire initial tuning process." Also licensed and renamed by manufacturers such as Gateway and HP
    XIMAPIload.exeAdded by the DOWNDEL-A TROJAN!
    NiMarkup ClientiUtil.exeEnables the iMarkup Client web page annotation utility to run in the background and be available in systray. Shortcut available via Start -> Programs
    UImatioimation.exeImation Disk Manager - enables you to create a password protected area on your Imation USB flash drive
    Ximchatimchat.exeAdded by a variant of the IRCBOT TROJAN!
    XIMClassSvhosl.exeAdded by an unidentified WORM or TROJAN!
    Ximcsslxmliwvug.exeDetected by Kaspersky as the SLAPER.U TROJAN! See here
    Nimekrigimekrig.exePart of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Japanese and this one is Korean)
    NIMEKRMIG6.1IMEKRMIG.EXEPart of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Japanese and this one is Korean)
    NImesh??Imesh is a file sharing system
    NImesh Auto Update??Update check for the Imesh file sharing system. Turn the update off under "options"
    XIMEvtMgr.exeIMEvtMgr.exeAdded by the KEYLOG-AR TROJAN!
    UImgIconImgIcon.exeDisplays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running
    Ximgit[path to file]Added by the BANKER-EM TROJAN!
    NImgStartImgStart.exeUsed by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs
    NImjpmig*.*IMJPMIG.EXEPart of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Korean and this one is Japanese). *.* represents the version number
    XIMJPMIG8.2msime82.exeAdded by the VB-CYG WORM!
    ?immcheck.exeimmcheck.exeRelated to I-FORCE driver for force feedback steering wheel?
    XImMsntimed.exeAdded by the WEBDOR.AK TROJAN!
    UIMOLIMOLApp.exeIncrediMail for Office Outlook Add-On
    NImonitorPlguni.exeMcAfee QuickClean 3.0 - removes internet clutter and unwanted programs
    Ximonitor[path to trojan]Added by the IMONI-A TROJAN!
    UIMONTRAYimontray.exeSystem tray monitoring of fans, temperature, voltage, etc for Intel motherboards. Only needed if you "overclock" or live in hot environment. Can also cause problems when running on a laptop if you change PCMCIA cards
    XIMprocessIM-svr.EXEIMNames adware
    UIMStartIMStart.exeInterMute security software related
    Ximwinsrvcacpmonsrv.exeAdded by the SLAPER.E TROJAN!
    XIMwireimwireup.exeSafeSurfing adware variant
    Xim_autornim_1.exeAdded by the IMAV.A WORM!
    Xim_autornim_2.exeAdded by the BAGLEDL-BO TROJAN!
    YInCDincd.exeAhead InCD packet writing software - similar to DirectCD. For Nero 5.0 or 5.5 (InCD3), it does not need to start with Windows. You can run InCD.exe manually before inserting an appropriately formatted CD-RW (CD-MRW) disk. For Nero 6.0, 6.3 or 6.6 (InCD4), it does need to start with Windows. It does not function correctly when you try to run it manually, and you will not have write access to MRW (Mount Rainier) formatted CD-RW (CD-MRW) or DVD-MRW disks. To regain write access and other features, InCD 4 must start with Windows
    NIncMailIncMail.exe"IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality"
    NInControl Desktop ManagerDMHKEY.EXEFor Diamond Multimedia video cards. Allows System Tray access to desktop utilities such as screen resolution. Available via Start -> Programs
    NIncredimailincredimail.exe"IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality"
    NIncredimailIncMail.exe"IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality"
    XIndex Servicedllhost32.exeAdded by the AGOBOT.CH WORM!
    UIndex WasherWashIdx.exeWindow Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
    XIndexindicatorIndexindicator.exeAdded by the LAZAR TROJAN!
    NIndexSearchIndexSearch.exeAssociated with PaperPort scanner software from ScanSoft
    UIndexTrayIndexTray.exePart of Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents"
    UIndicatorUtyIndicatorUty.exeFujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook, eg, when you press the hotkey for muting the sound, a loudspeaker icon with a cross on it is displayed
    Xinesvchosts.exeAdded by the RBOT.BNL WORM!
    XINETinetsync.exeMeplex adware
    XInet DataBaseInetdbs.exeAdded by the QEDS WORM!
    XInet Deliveryinetdl.exeInet Delivery adware
    XInet Deliveryinetdl_2.exeInet Delivery adware
    XInetapiNetapi.exeAdded by the NETDEVIL.14 TROJAN!
    Uinetcntrlinetcntrl.exeBsafe Online - internet filter
    ?InetConfinetconf.exe??
    UInetdINETD32.EXEWindows Inet Daemon from Hummingbird Communications. "Hummingbird Inetd has the advanced ability to conserve PC resources by listening for connection requests and launching server daemons". Provides PCs with the full functionality of a UNIX workstation
    Uinetinfo.exeinetinfo.exeExecutable used by MS Internet Information Server (IIS). If it's running, then so is IIS. Useful in knowing whether you require the patch for the Code Red worm. Comes with PWS (Personal Web Server) or NT4 and handles ASP-, PHP code (+ more)
    Xinetinfomon managerinetinfomon.exeAdded by the DONBOMB.A TROJAN!
    Xinetmgrinetmgr.exeActual Names (AdvSearch) Internet Keywords parasite
    XInetMSNmsnet.exeAdded by a variant of the SDBOT TROJAN!
    XInetServiceswsock32.exeAdded by the WOCK32-A TROJAN!
    Xinfamous.exewmplayer.exeAdded by unknown malware. WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup. Infamous.exe is identified by Panda antivirus as Trj/Briss.A
    XInfeStopInfeStopRemover.exeInfeStop spyware remover - not recommended, see here
    UInfo Selectis.exeInfo Select from Micro Logic - personal information manager
    XInfo32xInfo32x.exeAdded by the GEMA TROJAN!
    XInfoDatarundll32.exe ********.dll, realset [* = random char]Added by the VUNDO TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    UInfoPenMSNInfoPenIM.exeInfoPenMSN is a MSN Messenger plugin that allows you to send data written/drawn by hand
    ?Infoplay.exeInfoplay.exeWritten by New Media Properties, LLC and you're asked if you want to download and install it if you visit one of their search engine websites (which I chose not to). What does it do and is it needed?
    XInformation Updateiu.exeDetected by Kaspersky as the CENTIM.CH TROJAN!
    UInfra-red MonitorIRMON.EXESystem Tray access to infra-red devices. Not required unless you use infra-red devices
    Xinfusinfus.exeAdult content dialler
    UInfuzerInfuzer.exeInfuzer - "is a service that copies dates from the web or an email straight to your electronic calendar". Beware of the following adware trait - "Infuzer provides web site owners with a unique opportunity to communicate with their visitors in a way that is useful and relevant to them, as well as increasing return visits and brand awareness, and providing new e-commerce opportunities"
    Xinfwininfwin.exeVX2.Transponder parasite updater/installer related
    XInit32Init32.exeAdded by the WINEX.A TROJAN!
    XInitial Pageinstall.exeEasySearch browser hijack installer
    YInitialize8x88x8_init.exeTool that initializes a Pinnacle PCTV card - maybe in capture or in showing overlay
    Xinjobinjobs.exeAdded by the BINJO TROJAN!
    NInk MonitorInkMonitor.exeAssociated with Epson (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line
    NInkWatchInkWatch.exeAssociated with Canon (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line
    YInoRPCInoRpc.exeAssociated with eTrust Antivirus/InoculateIT
    YInoRTInoRT9x.exeAssociated with the Realtime Monitor of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. For NT/2K/XP users you may need a patch if seeing high CPU useage
    UInoTaskInoTask.exeScheduled scans and signature updates for eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. Leave enabled unless you manually update signatures or perform routine scans. If enabled it can result in high CPU useage when performing updates
    XiNoticeiservice.exeAdded by a variant of an MSN worm that tries to lure people to an infected site by using nude pictures and videos
    ?insCOA5insCOA5.exe??
    XInsiderInsider.exeDetected by PCTools as the AGENT.KMC TROJAN! See here
    UInstaAlertInstaAlert.exe"Kayako InstaAlert allows you to receive realtime alerts whenever a ticket gets updated under the assigned departments. The application displays popups as and when the tickets are created or replied to allowing you to answer your customer requests and issues promptly"
    XInstaFinderKInstaFinderK inst.exeInstaFinder adware
    XInstallInstall.exeAdded by the BANCBAN-HG TROJAN!
    XInstall part IIupdates.exeAdded by the RELFEERWORM!
    ?Install Pending Filessifxinst.exeUninstall program for Lanovation's Prism Deploy and Prism Pack adminstrators software deployement tools. For specific information see here. Is it required?
    NInstallAurealDemosInstallAurealDemos.jsUsed to initialize the Aureal A3D demos InstallShield wizard
    UInstallBuddyIbtna.exeInstallBuddy - automatically translates and installs your desktop documents, such as Adobe PDF, HTML, Microsoft Word, Excel and PowerPoint files, to your Palm organizer when you HotSync
    XInstallCleanerInstallCleaner.exeAdded by the ANYHOMB.F TROJAN!
    XInstalled shell32.dllOffice.exe...Added by a variant of the LOVGATE WORM!
    XInstallerdial.exeMalware - detected by Kaspersky as the AGENT.MM TROJAN!
    ?InstallNAIProductSETUP.EXECould be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error?
    XInstallProvidernewsoftware2007install.exeWinAntiVirus Pro 2007 and Privacy Protector misleading security software - not recommended, see here
    XInstalls SP2[path] repcale.exe [path] palsp.exeAdded by a variant of the RANDON.AN WORM!
    UInstallstubinstallstub.exeTool for Outlook and Outlook Express from Plaxo for organising and keeping contacts organised and updated and providing online access to your contacts and access from PDA or mobile phone
    XInstance 001[path to worm]Added by the ALASROU-A WORM!
    XInstant Accessrundll32.exe EGDHTML_1023.dll, InstantAccessInstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
    XInstant Accessrundll32.exe eg_auth_****.dll, InstantAccess [**** = digits]InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
    XInstant Accessrundll32.exe EGCOMLIB_****.dll, InstantAccess [**** = digits]InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
    XInstant Accessrundll32.exe EGCOMSERVICE_****.dll, InstantAccess [**** = digits]InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
    XInstant Accessrundll32.exe p2esocks_****.dll, InstantAccess [**** = digits]InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
    XInstant Accessmwsrvacc.exeInstantAccess premium rate adult content dialer
    XInstant Accesslinewsrv.exeInstantAccess premium rate adult content dialer variant
    XInstant Buzz DaemonIBDaemon.exeInstant Buzz adware
    XInstant Messenger Serviceimservice.exeDetected by Kaspersky as the HEUR TROJAN!
    NInstant Update Centerreminder.exeFrom Broderbund's PrintMaster 10. It is an event reminder (for calendar dates, etc). Delete from the startup using Startup Manager program because it keeps re-checking itself when using MSCONFIG.  PrintMaster 11 uses filename PMremind.exe - it has to be unchecked in startup in the same manner
    UInstant Wireless Configuration UtilityWUSB11cfg.exeUtility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration
    UInstant Wireless Configuration UtilityWPC11Cfg.exeUtility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration
    NInstantAccessINSTAN~1.EXEFrom TextBridge Pro 9.0 OCR scanner software. Available via Start -> Programs
    UInstantDriveInstantDrive.exePinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer's hard drive. Part of InstantCD/DVD burning software
    XInstantPleasureinstantpleasure.exeAdult content dialler
    XInstantPleasureXXXinstantpleasurexxx.exeAdult content dialler
    NInstantTrayPCLETray.exePinnacle InstantCD/DVD disc creation software. Tray icon enabling a pop-up menu that lets you call up any of Instant CD/DVD's tools with one click. Can be started manually
    Xinstitinstit.batAdded by the OPASERV.H WORM!
    XinstitINSTIT.BATAdded by the OPASERV.K WORM!
    ?InstUtlR.exeInstUtlR.exe??
    Xintdctrridctup20.exeSafeSurfing adware variant
    XIntec Service Driversmsmsgrs.exeAdded by the SDBOT-ADN WORM!
    XIntec Service Drivers[path to worm]Added by the RBOT-GLU WORM!
    XIntec Service Driverswing32.exeAdded by the RBOT.HAZ WORM!
    XIntec Services Driverrswinrvc.exeAdded by a variant of the SDBOT WORM!
    UIntegardTrayIntegardTray.exeSystem Tray access to Integardparental control software from Race River Corp
    UIntel Active Monitorimontray.exeSystem tray monitoring of fans, temperature, voltage, etc for Intel motherboards. Only needed if you "overclock" or live in hot environment. Can also cause problems when running on a laptop if you change PCMCIA cards
    XIntel Audio Studio V2.0fmideploy.exeDetected by VBA32 as the BIFROSE.ADR TROJAN!
    XIntel Drivercsrs.exeAdded by a variant of the SDBOT WORM!
    UIntel File Transferxfr.exePart of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients
    UIntel PDSpds.exeIntel Ping Discovery Service (PDS). Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients. Will start the dial-up if installed and enabled
    UIntel Product Number UtilityIntelProcNumUtility.exeIntel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here
    NIntel PROSet Tray Iconpromon.exeSystem Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features
    XIntel Service Driversmsconfig16.exeAdded by the MSCONFIG16 TROJAN!
    XIntel system toolhookdump.exeAdded by the SPYRE-H TROJAN!
    XIntel system toolwinnook.exeAdded by the SPYRE-C TROJAN!
    XIntel system toolsvehost.exeAdded by the AGENT-EBT TROJAN!
    XIntel system worksiis.exeAdded by the RBOT.QGA WORM!
    UIntel(R) Common User Interfacehkcmd.exePart of Intels Common User Interface for chipsets with integrated graphics controllers - which allows user to change different driver properties through Windows User Interface. If the user wishes to have "HotKey" access to Intel's customised graphics properties, it is required, otherwise not. It can be disabled via the Display Properties in the Control Panel
    NIntel(R) Common User Interfaceigfxpers.exePart of Intels Common User Interface for chipsets with integrated graphics controllers - which allows user to change different driver properties through Windows User Interface. Not known exactly what it does but apparently it isn't required
    Xintel32.exeintel32.exeAdded by the SmitFraud alias SPYJACK-B TROJAN!
    UIntel? Common User Interfaceigfxtray.exePart of Intels Common User Interface for chipsets with integrated graphics controllers - which allows user to change different driver properties through Windows User Interface. Quick access to the control panel via a System Tray icon. Available via Start -> Settings -> Control Panel
    UIntelAPMClientamclient.exeLANDesk Management Suite software component
    NIntelAudioStudioIntelAudioStudio.exe"Intel Audio Studio combines Intel? High Definition audio hardware features with Sonic Focus* Audio Refinement and Dolby* technologies to provide you with a comprehensive tool that puts you in control of your audio experience". Audio utility supplied with Intel motherboards
    XInteliSyssmss.exeAdvertisingvision adware! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
    Xintell32.exeintell32.exeAdded by the SmitFraud alias Desktophijack.C TROJAN!
    Xintell321.exeintell321.exeAdded by the SPYJACK-B TROJAN!
    XIntelliflag_be.exeIntelliflag_be.exeAdded by the Intelliflag SPYWARE!
    UIntelliPointpoint32.exeMicrosoft Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features
    UIntelliPointipoint.exeMicrosoft Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features
    UIntellitypetype32.exeFor MS programmable keyboards. If you disable Intellitype in Startup, any "Hot Keys" that are changed by the user to perform functions other than default settings, defer back to their default settings unless you have changed them
    UIntelMEMIntelMEM.exeRelated to connection events on an Intel chipset based modem. It can alert you if the telephone line is being used when you're trying to get online (when you're using dial-up). It can also alert you if your modem line is disconnected. Furthermore, it can alert you if you have made a wrong connection with your modem line
    UIntelProcNumUtilitycpunumber.exeIntel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here
    YIntelWirelessifrmewrk.exeAssociated with the Intel PRO/Set Wireless software
    UIntelZeroConfigZCfgSvc.exeZero Config MFC Application, part of Intel's ProSET utilities and installed by the drivers for many of Intel wireless network cards - essential to the proper functioning of many of the Intel ProSET utilities (but not all) and these System Tray ProSET utilities are a must if you are using your wireless connection, if only so you know when the signal is fading or dropping. The problem is that, in some PCs, ZCFGSVC can be incredibly badly behaved : taking up to 100% of CPU time and therefore resulting in an extremely slow PC, preventing the installation of software or Windows updates, or causing "Not Responding" or "End this Program" shutdown problems. If you experience this, try first the very latest drivers from Intel or your laptop manufacturer. If that still does not solve the problem and you have WinXP/2003, try setting the "Wireless Zero Configuration" service to disabled
    ?Intense Registry ServiceIntEdReg.exe /CHECKIntense Educational Ltd - Language Office Software. Is it required?
    XInterceptedSystem[path to worm]Added by the ANACON-B WORM!
    YInterCheck MonitorIcmon.exePart of Sophos ant-virus sofware
    YInterCheckMonitorICMON.EXEPart of Sophos anti-virus sofware
    XInterdllInterdll.exeAdded by the DELF family of TROJANS!
    XInternal[trojan filename]Added by the SMOTHER and TRANSLAT TROJANS!
    XInternalregedit.exe /s %windir%c:[month number]Added by the FORTNIGHT.D TROJAN!
    XInternal Memory Filesysintmemory.exeAdded by the RBOT-GKT WORM!
    XInternalSystrayKazza.exeAdded by a variant of the OPTIX TROJAN! Note - unlike the valid KaZaA executable, this is located in C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K), or C:WindowsSystem32 (WinXP)
    Xinternatinternat.exeAdded by the LYDRA-F TROJAN! Note - the real internat.exe resides in %windir%system (where %windir% is the Windows directory - C:Windows or C:Winnt) whereas this version resides in %windir%
    XInternatsystray.exeAdded by the ALADINZ.P TROJAN! Note - this is not the legitimate systray.exe process. If you right-click on the real systray.exe the "Properties" reveal it to be a Microsoft file
    XInternatmsgsrv32.exeAdded by the NYRUBOT-A WORM!
    XInternat[trojan filename]Added by the CMJSPY-Y TROJAN!
    XInternat Confbootconf.exeHomepage hijacker, redirecting to coolwwwsearch.com; see for example here
    Ninternat.exeinternat.exeMicrosoft language selection icon in system tray, located in the System (Win98/Me) or System32 (WinNT/2K/XP) folder
    XInternat.exeinternat.exeAdded by the NETSNAKE TROJAN! Note - the real internat.exe resides in %windir%system (Win98/Me) or %windir%System32 (WinNT/2K/XP) (where %windir% is the Windows directory - C:Windows or C:Winnt) and has a "?" icon wheras this version resides in %windir% and has a ZIP icon
    XinternctWinSocks5.exeAdded by the GRAYBIRD.F TROJAN!
    Xinternetsmss.exeAdded by the MIFENG-K TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!
    XInternetInternet.exeAdded by the PWS-CS TROJAN!
    XInternetrecruit.exeAdded by the RBOT-AJG WORM!
    Xinternet[trojan filename].exeAdded by the MIFENG-D TROJAN!
    XInternetwinlogom.exeAdded by a variant of the SDBOT WORM!
    XInternetnteusodp.exeAdded by the RBOT-GFJ WORM!
    Xinternetwinsas32.exeAdded by a variant of the SDBOT WORM!
    Xinternetlsass.exeAdded by the DSPY-A TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!
    XInternetalm7tas.exeAdded by a variant of the RBOT WORM!
    UInternet Answering MachineIAMNET~1.EXEFrom Callwave. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access
    UInternet Answering MachineIAM.exeFrom Callwave - offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access
    XInternet Application DriverexpIorer.exeAdded by the IRCBOT-WK TROJAN!
    UInternet Call DirectorICD.EXETELUS Internet Call Director (ICD) provides Internet users with real-time call notification while connected to the Internet
    UInternet Call ManagerICM.EXEStarts Internet Call Manager dialog box and/or taskbar icons at bootup. This is a subscription program from internetcallmanager.com that monitors a dialup phone line for incoming calls and handles voicemail
    XInternet Configsvchosts.exeAdded by the SDBOT TROJAN!
    XInternet Connection Wizardstisvsq.exeEasySearch adware
    XInternet Connection Wizard[path to trojan]Added by the SMUTSRCH-A TROJAN!
    XInternet Connection Wizardstisvsq1.exeAdded by the DLOADR-AWD TROJAN!
    XInternet Content PublisherICP.EXEAdded by the RBOT-UD WORM!
    UInternet Disk CleanerCLEARH~1.EXE"Internet Disk Cleaner from Elongsoft "protects your privacy by cleaning up all Internet tracks and past computer activities"
    UInternet Download Acceleratorida.exeInternet Download Accelerator download manager
    XInternet download manager serviceidman.exeAdded by the RBOT-BMS WORM!
    XInternet Exploere Servicesurlmon32.dll.exeAdded by the EVIAN.C WORM!
    XInternet Explore MicrosoftlEXPLORE.EXEAdded by the RBOT-AOF WORM! Note - the executable is spelt with a lower case "L" rather than an lower or upper case "i" which is the case with Internet Explorer
    XInternet Exploreriexplorer.exeAdded by the LORSIS WORM! Note - the legitimate IE (iexplore.exe) does not figure in Msconfig/Startup unless added manually and this loads from the "RunServices" key
    XInternet ExplorerIEXPLORE.EXEAdded by the RBOT-EY WORM! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    XInternet ExplorerIExplorer.exeAdded by the NETHIEF-O TROJAN!
    XInternet Explorerhttp.exeAdded as part of a new potential CWS infection, and part of a suite of programs that installs a web server, php, ftp server, socks, and mail server on your computer without your knowledge. These files are known to be part of an infection that transmits information about your bank accounts, passwords, and other financial information. It should be deleted immediately, you should enable your firewall, and you should contact your financial services in order to report the issue and to have your passwords changed
    XInternet Exploreriexpiore.exeAdded by the RBOT-AZC WORM!
    XInternet Explorer ConfigurationIEXPLORE.EXEAdded by the SDBOT-UL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup unless you add it manually! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    XInternet Explorer Securityiexplore.pifAdded by the RBOT-ALQ WORM!
    XInternet Explorer Updaterlexbac.exeAdded by the DOWNLOAD TROJAN!
    XInternet Explorer Updateriexplorer.exeAdded by the REUR.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)
    XInternet Firewall Layertsqla.exeAdded by a variant of the SPYBOT WORM!
    UInternet History EraserHERASER.exeInternet History Eraser - deletes your browsing tracks
    XInternet Loader1MSInstall61.exeAdded by the KWBOT.B WORM!
    XInternet Mail and Newsmsqdevl.exeEasySearch adware
    XInternet Mail and News[path to trojan]Added by the SMUTSRCH-A TROJAN!
    XInternet Mail and Newsmsqdevl1.exeAdded by the DLOADR-AWD TROJAN!
    UInternet Optimizeroptimize.exeInternet connection optimizer. Leave this enabled if you find it improves your connection
    XInternet Optimizeroptimize.exeInternet Optimizer parasite, MoneyTree variant - ActiveX control used to download premium-rate dialers
    XInternet Security Servicemsq32.exeAdded by the RBOT-GFP WORM!
    XInternet Security Servicemsq23.exeAdded by the RBOT-GQL WORM!
    XInternet Security Servicemsql23.exeAdded by the RBOT-GML WORM!
    XInternet Security Servicemysqlwin32.exeDetected by Trend Micro as the RBOT.UX TROJAN! See here
    XInternet SendMore log.exeUnidentfied adware
    XInternet Serverinetsrv.exeAdded by the STARTPA-EM TROJAN!
    XInternet Serviceintersvc.exeAdded by the SPYBOT-DE WORM!
    Xinternet servicesyscfg32.exeAdded by the RBOT-QS WORM!
    Xinternet servicessvhost.exeAdded by a variant of the RBOT WORM!
    Xinternet servicesvho0st98.exeAdded by the RBOT.EAT WORM!
    XInternet Servicessystemdev.exeAdded by the SDBOT-PW WORM!
    XInternet Servicesinternet.exeAdded by the MYTOB.BT WORM!
    XInternet Servicesinterserv.exeAdded by the RBOT.BNT WORM!
    XInternet ServicesNetsvc.exeAdded by the MYTOB.MN WORM!
    XINTERNET SERVISESwinz32.exeAdded by the KWBOT.Z WORM!
    YInternet Sharing Serveriss_srvr.exeIntel AnyPoint internet sharing software. Now discontinued
    XInternet Suspentionstory.exeAdded by the WOOTBOT.HV WORM!
    NInternet SweeperSweeper.exeInternet Sweeper - removes unnecessart left over files after browsing the internet
    UInternet TimerITIMER.exeShareware dial-up connection call cost calculator from Ratsoft
    XInternet Washer Proiw.exeInternet Washer manages temporary browser files, cookies, etc - a 'trial' Internet Washer Pro seems to have been widely stealth-installed around March 2003
    XInternet.exeInternet.exeAdded by the MAGICCALL VIRUS!
    Xinternet.exeyinyin3345.vbsAdded by the YINI MACRO!
    XInternet2 Optimizerwkfix.exeAdded by a variant of the RBOT WORM!
    XInternetExplorer2windows.exeAdded by the SDBOT-CZP WORM!
    XInternetExplorer32iexplore32.exeAdded by the RBOT-GRA WORM!
    XInternetShieldINTERN~1.EXEInternetShield misleading security software - not recommended, see here
    UInternetSpyInternetSpy.exeInternet Spy - freeware keylogger that tracks all visited websites including the date and exact time these sites were visited. The information is stored in a file that may be accessed by the person who knows where it is saved. Remove unless you installed it yourself!
    XInternetWasherProiw.exeInternet Washer manages temporary browser files, cookies, etc - a 'trial' Internet Washer Pro seems to have been widely stealth-installed around March 2003
    XINTERNET_SERVISESwinz32.exeAdded by the SDBOT.Q TROJAN!
    UInternodeUsagemum.exeAustralian ISP's free monthly download meter
    XInterntInternt.exeAdded by the PEEPER or CARUFAX.A TROJANS!
    XIntersoft Msngrintersoftmsngr.exeAdded by the AGOBOT-NW WORM!
    NInterTrust Quick Startit_cpq~1.exeInterTrust offers something known as Digital Rights Management to control legal software download and other E-commerce related business
    XInterUWINDRV.EXEAdded by the IRCINTER.A TROJAN!
    NIntervideo Win Cinema ManagerWinCinemaMgr.exeWinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
    NIntervideo Win Cinema ManagerWINCIN~1.EXEWinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
    NIntervideo WinCinema ManagerWinCinemaMgr.exeWinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
    NIntervideo WinCinema ManagerWINCIN~1.EXEWinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
    NIntervideo WinSchedulerWinScheduler.exeWinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs
    NIntervideo WinSchedulerSchSvr.exeWinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs
    UInterWARNinterwarn.exeInterWARN by Storm Alert Inc. Provides customized, automated access to critical weather and civil emergency information from the US National Weather Service. Required if audio and screen crawler alerts are desired. Also available via Start -> Programs
    XIntespentionIEXPLORE.exeAdded by the FORBOT-FL WORM! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    XIntmgrIntmgr.exeAdded by the GEMA TROJAN!
    XintranetSYS32CFG.EXEAdded by the SPYBOT-DW WORM!
    XIntranetintranet.exeAdded by the CHIMOZ.AC TROJAN!
    XIntranet Exploreriexplorer.exeAdded by a variant of AHENT-CAX TROJAN!
    XIntrenatIntrenat.exeAdded by the LEMIR.E TROJAN!
    NIntroducing Media ManagerSPLASHA.EXEMS Media Manager tour. Not required
    NIntroduction-Registration??For Compaq PC's. Should only run first time, PC Introduction & Compaq registration
    XIntruderAlertia99.exeIntruder Alert '99 from Bonzi - spyware
    XIntSys1[path to trojan]Added by the BANLOA-ASE TROJAN!
    UInventory ScanLDISCN32.EXELANDesk Management_Suite software component
    XIoadqmMedia Player.exeAdded by the HAWAWI WORM!
    NiobiiobiClient.exeiobi Home - a mail/voice service by Verizon
    Yiolo AntiVirusioloAV.exeiolo AntiVirus
    Yiolo Personal FirewallioloFW.exeiolo Personal Firewall
    UIolo Task AgentTask_Agent.exeIolo System Mechanic Task Agent. Scheduled maintenance
    Niolo Utility BarSMUtilityBar.exeIolo System Mechanic Utility Bar - can be launched manually
    UioloDelayModuledelay.exePart of Iolo System Mechanic. Used to delay the start of an application which loads automatically as Windows loads
    UIomega Automatic Backupibackup.exeIomega Automatic Backup - automatic backups for use with Iomega portable HDD
    UIomega Automatic Backup 1.0.1ibackup.exeIomega Automatic Backup - automatic backups for use with Iomega portable HDD
    NIomega Backup Schedulerdtiom98.exeUsed by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs
    UIomega Disk IconsIMGICON.EXEDisplays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running
    UIomega Drive IconsIMGICON.EXEDisplays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running
    UIomega ImIconXPimiconxp.exeIomega REV System Software - allows your Iomega REV drive to interact with the operating system via the Iomega REV UDF file system, and provides drag-and-drop file access, access and write protection, and formatting of the disks
    ?Iomega QuickSyncQuicksync.exe??
    NIomega Startup OptionsIMGSTART.EXEUsed by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs
    NIomega WatchIOWATCH.EXEUsed by Iomega drives. Available via Start -> Programs
    NIomegaWareCOMMANDER.EXEUsed by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs
    UIomon98.exeIomon98.exePC-Cillin 98 real time virus check. Can cause floppy disk accesses to hang
    Xioroxxo microsoft suxsystem32.exeAdded by a variant of the RBOT WORM!
    XIP Packet Redirect Service ipredirect.exeAdded by the FORBOT.SM WORM!
    XIP Stackipstack.exeAdded by the AGOBOT.CW WORM!
    XIP**.exe [* = random char]IP**.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
    XIP**32.exe [* = random char]IP**32.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
    NiPalmmon.exeInstalled with a Panasonic iPalm digital camera. Used to upload photos from the camera. If your camera is not connected (via USB port) you do not need this program loaded
    XIPC Connectionipcconn.exeAdded by the RBOT-AEG WORM!
    XIPC Spool Managerwnmgre.exeAdded by the SDBOT-ZC WORM!
    XIPC Spool Managerwinspec.exeAdded by the SDBOT-BLU WORM!
    Xipcfg.exeipcfg.exeAdware - detected by McAfee as a variant of the ADCLICKER-BM TROJAN!
    XIPConfigsvcxnv32.exeAdded by the HACARMY.E TROJAN!
    XIPConfigsvcxnw32.exeAdded by a variant of the HACARMY.E TROJAN!
    XIpCtrlipcon32.exeAdded by an unidentified VIRUS, WORM or TROJAN!
    XIPFWipwf.exeAdded by the DLOADER-YF TROJAN!
    ?IPHSendIPHSend.exeAOL related. What does it do and is it required?
    XIPInSightLAN 0*ipclient.exeInstalled with Verizon DSL accounts. IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. This one constantly "phones home" and wastes resources. * represents 1 or 2
    NIPInSightMonitor 0*ipmon32.exeInstalled with Verizon DSL accounts. IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. * represents 1 or 2
    YIPinstN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
    ?iPlusAgent2iAgent2.exeRelated to iriver portable media products. What does it do and is it required?
    Xipmon.exeipmon.exeAdded by the RECERV or R3C.B TROJANS!
    XIpNetworkipnetwork.exeMaxifiles adware
    XIpnukerIpnuker.vbsAdded by the INKER.B WORM!
    NIPO3IP Operator 2005.exeIP Operator 2005 - found on LG Electronics Notebook. The applet makes network connections easier to view and manage than does the standard Windows Network Connections tool. The WLAN module is easy to turn on or off with the press of a single button
    XIpod Help[9 random letters].exeAdded by a variant of the RBOT WORM!
    XiPOD USB DriverIPODUSB.EXEAdded by a variant of the RBOT WORM!
    XiPod USB ServiceiPODService.exeAdded by a variant of the RBOT WORM! Do NOT confuse with the Apple iPod process of the same name. The legitimate iPod file will always be located in the Program FilesiPodbin folder, and is implemented as a system service, thus NOT listed in Msconfig/Startup!
    UiPodManageriPodManager.exeApple iPod Management software for the iPod MP3 player. Allows updating, formating, restoring and other functions associated with iPods
    ?iPodWatcheriPodWatcher.exeAssociated with Apple's iPod MP3 player. Detects when the iPod is connected?
    XIPOT Service Driverscompaq.exeAdded by a variant of the FUROOTKIT TROJAN!
    XIPOT Service Driverscompaq.exeAdded by a variant of the FUROOTKIT TROJAN!
    XIPOT USB Service DRIVERhpsebc087.exeAdded by the SDBOT-WA WORM!
    XIPOT USB Service DRV32hpsebc08.exeAdded by the SDBOT-WH WORM!
    NIPPDetectIPP4Detect.exePart of Presto! Mr.Photo - "an ideal program for creating, sharing, and manag-ing digital images and videos"
    Xipregipreg.exeAdded by the ZAGABAN-H TROJAN!
    ?iPrint LPT Redirectornipplpte.exeRelated to Novell iPrint - "a printing solution that enables you to send documents to printers located throughout the Net." Is it required?
    NiPrint Trayiprntctl.exeNovell? iPrint - based on Novell Distributed Print Services - enables you to send documents to printers located throughout the Net
    UiProtectYouip.exeiProtectYou - internet filtering/parental control and network monitoring software
    XipruniPY.exeiProtectYou spyware
    UipsecdialerIPSECD~1.EXECisco VPN Client - lets local users gain Administrator privileges on the operating system
    Uipsecdialeripsecdialer.exeCisco VPN Client - lets local users gain Administrator privileges on the operating system
    YIPSecMonIPSecMon.exeMicrosoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet
    XIPTable ConfigurationWinipcfgs.exeAdded by a variant of the RBOT WORM!
    Niptrayiptray.exeSystem Tray access to Intel Desktop Utilities - "provides you with the means to monitor system temperatures, voltages, fan speeds, and hard drive health; view detailed system information, and test your system hardware for common errors"
    XIPv6 Helper Drivercsass.exeAdded by the AGOBOT.TC WORM!
    XIPv6 STUN Servicenetstun.exeAdded by a variant of the SDBOT WORM!
    NIPWIPW.exeInternet Phone Wizard from Actiontec - Voice over IP (VoIP) that allows you to "make and receive free Internet calls on your regular phone" whilst "at the same time, make and receive regular (landline) calls on your phone"
    Nipwusbipw.exeRelated to Internet Phone Wizard from Actiontec - Voice over IP (VoIP) that allows you to "make and receive free Internet calls on your regular phone" whilst "at the same time, make and receive regular (landline) calls on your phone"
    Xipwfipwf.exeAdded by the SCHOEBERL TROJAN!
    XIpWinsipwins.exeIPWins adware
    Xipxwshelipxwshel.exeAdded by the WAREZOV.DG WORM!
    ?IQES.exeiqes.exe??
    UIr41_32.axregsvr32.exe Ir41_32.axIntel® Indeo® video 4.4 Decompression Filter related. The "Ir41_32.ax" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    Xirassyncirasyncd.exeIRASSync adware
    Xirc sessionsessionmgr.exeAdded by the SDBOT-ACE WORM!
    YIREIKEIreIKE.exeMicrosoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet
    NiRis Active Monitorwinmon32.exeIris Antivirus - discontinued, replace with good alternative
    NiRiS AntiVirus Active MonitorWIMMUN32.exeIris Antivirus - discontinued, replace with good alternative
    UiRiver AutoDBMLService.exeAssociated with the iRiver Music Manager
    NiRiver UpdaterUpdater.exeUpdates for the iRiver Music Manager - used with their digital music players
    UIrMonIRMON.EXESystem Tray access to infra-red devices. Not required unless you use infra-red devices
    ?IRPMonitoritcnmon.exe??
    Xirssyncdirssyncd.exeSafeSurfing adware variant
    XIrwftp[path to trojan]Added by the BANCOS-AP TROJAN!
    Xirwftpiexplorer.exeAdded by the BANKER-AN TROJAN!
    Xirwftpftpmon.exeAdded by the BANCBAN-BO TROJAN!
    UIrXferIrXfer.exeMicrosoft Infrared Transfer application
    Xir_ftpir_ftp.exeAdded by the IRFTP TROJAN!
    Xir_ftpirwftp.exeAdded by the BANCOS.H TROJAN!
    NIS CfgWizcfgwiz.exeNorton Internet Security configuration wizard
    XIsassIsass.exeAdded by the FUTRO TROJAN!
    XIsassRenascimentoIssas.exeDetected by Kaspersky as the BANKER.GAX TROJAN! See here
    UISBMgr.exeISBMgr.exeRelated to Sony ISB Utility. This program is non-essential process to the running of the system, but should not be terminated unless suspected to be causing problems
    Xiscchiscch.exeAdded by the LCPRANK-A WORM!
    Nisdbdcisdbdc.exeFor Compaq PC's. May install properties in dial-up networking when you register with an ISP
    UisDeleteMeisDel.batUsed by Norton Internet Security to remove certain files and directories on reboot when uninstalling their product
    NISDN MonitorLinksts.exeTray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards, such as MRi). This icon enables you to monitor or configure your ISDN card. Once you have configured your ISDN card correctly, you will never need to use this icon
    UISDNwatchIWatch.exeFRITZ!X ISDNWatch - "dialing filter for more security and control on the ISDN PC. The PC is doubly protected against dialer programs and premium-service numbers: ISDNWatch allows the user to block calls to and from both individual numbers and whole number blocks"
    XiSecurity appletrundll32.exe iSecurity.cpl, SecurityMonitorDetected by Trend Micro as the DLOADER.UZO TROJAN! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
    UISHelphelp.exeISpy is a security risk that logs keystrokes and captures screenshots. If you didn't install this yourself uninstall it
    UiShieldiShield.exe"GuardWare iShield blocks pornographic images when you surf the Internet on your computer using a web browser"
    Xishost.exeishost.exeAdded by the XJ TROJAN!
    YISLP2STAISLP2STA.EXEA process from Cisco Systems Inc associated with Windows Update for wireless NIC drivers
    XISMModuleISMModule.exeHyperlinks Rotator (aka ISMonitor) adware
    XISMModule2ISMModule2.exeHyperlinks Rotator (aka ISMonitor) adware
    XISMModule3ISMModule3.exeHyperlinks Rotator (aka ISMonitor) adware
    XISMModule4ISMModule4.exeHyperlinks Rotator (aka ISMonitor) adware
    XISMPack5ISMPack5.exeHyperlinks Rotator (aka ISMonitor) adware
    XISMPack6ISMPack6.exeHyperlinks Rotator (aka ISMonitor) adware
    XISMPack7ISMPack7.exeHyperlinks Rotator (aka ISMonitor) adware
    YISP.COM High Speedslipgui.exeUser interface for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet, Wanadoo, Terra, OnSpeed, United Online and AOL Canada. Required if the user's account is locked in to that proxy server
    XISPSERVICEpsycho.exeAdded by the IRCFLOOD-O TROJAN!
    UiSpyNOWispynow.exeiSpyNOW - remote monitoring and surveillance software
    XIsrafelIsrafel.vbsAdded by the GAGGLE.D or GAGGLE.E WORMS!
    NIsReminderISPopup.exeRelated to GuardWare iShield - this is the registration reminder for the trial version, so not required in startup
    XISSinet.exeMeplex adware
    Xissearch.exeissearch.exeAdded by the ZLOB-QF TROJAN!
    XissEnc32SvrissEnc32.exeAdded by a variant of the RBOT WORM!
    NISSI EZUpdate Serviceissimsvc.exePart of IBM Global Services - used internally by IBM for automatic updating of software and Microsoft patching
    UISStartISStart.exeLogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the "U" rather than "Y" recommendation
    YISSVCISSVC.exePart of Norton Internet Security Suite
    YISS_Certtoolcerttool.exeIBM Client Security Certification Tool
    XIST Serviceistsvc.exeISTBar adware
    Xist service uninstall[random filename]ISTBar parasite related
    Xistinstall zazzer.exeistinstall zazzer.exeUnidentified adware downloader/installer
    UISTraypctsTray.exePart of Spyware Doctor anti-spyware from PC Tools
    NISUSPM StartupISUSPM.exeInstallShield Update Service Scheduler. Automatically searches for and performs any updates to the software so you're always working with the most current version
    NISUSSchedulerissch.exeInstallShield Update Service Scheduler. Automatically searches for and performs any updates to the software so you're always working with the most current version
    UISW.exeISW.exeRelated to Internet Security Wizard from AT&T (formerly BellSouth Premium Internet Security) alerts users about any potential security threats. It should not be uninstalled unless the user wants to completely remove all traces of AT&T Internet Security Suite
    Xisxaisxa.exeAdded by the SMALL-EIV TROJAN!
    NiSysCleaneriSysCleaner.exeiSysCleaner - a simple tool that searches for junk files on your computer and allows you to delete them. Simple cleaning maintenance can be done by the user
    Xisystemisystem.exeAdded by the CHORUS-A TROJAN! Searchforfree browser hijacker
    XItalUitalfds.exeAdded by a TROJAN! See here TROJAN!
    UItkItk.exeIn The Know - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it
    Uitk.exeitk.exeInsert ToggleKey by Mike Lin. ITK sounds a tone whenever you press Insert
    UiTouchiTouch.exeiTouch loads the iTouch configuration program for Logitech keyboards. It's needed if your keyboard has shortcut buttons and if you use them. It's also needed if your keyboard does not have the num lock, caps lock, and scroll lock lights on it and you use the on-screen displays for num lock, caps lock, and scroll lock
    NItsDeductiblePopUpItsDeductible.exeItsDeductible from Income Dynamics. Calculates your noncash donations quickly and easily. This startup entry checks a registry entry for the next 'PopUp' date and if it is a past or current date displays a program related tip
    XITUNESitune.exeAdded by the RBOT-ZU WORM!
    XITUNESitunes.exeAdded by the OSCABOT-L WORM! Note - this file will be placed in the WindowsSystem32 or WinntSystem32 folder, and should not be confused with the (legitimate) Apple iTunes process, always located in the Program FilesiTunes folder
    XItunesdials.exeDetected as Trojan-Dropper.Win32.Agent.mm by Kaspersky Anti-Virus
    YiTunes HelperiTunesHelper.exeInstalled with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation
    XiTunes MusiciTunesHelper32.exeAdded by a variant of the SDBOT WORM!
    XiTunesAgentita.exeAdded by the TACTSLAY.U TROJAN!
    Xitunesffitunesff.exeAdded by the EB adult premium dialer
    YiTunesHelperiTunesHelper.exeInstalled with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation
    Uitypeitype.exeMicrosoft IntelliType Pro related. Allows you to map the extra function keys to any program you like. The extra keys are set to defaults such as Messenger, Mail, My Document, etc. Not required unless you want to use the extra keys
    NIusagenetdet.exeInternet Usage Monitor - utility to calculate the cost and time on the internet via dial-up
    Xiut75uzcx.exeAdded by the DLOADER-AXV TROJAN!
    XivHosttaskManager.exeAdded by a variant of the SPYBOT WORM! See here
    NIVPServiceMgrivpsvmgr.exeToshiba IVP Service Manager application which appears as a red satellite dish icon in the System Tray. This is Toshiba's equivalent to the Windows Automatic Update feature as, whenever you are connected to the Internet, it will check for Windows updates and Toshiba updates
    Xivy.exeivy.exeAdded by the AGENT-ENZ TROJAN!
    NIW ControlCenteriwctrl.exePinnacle Systems InstantWrite enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basis
    Uiwctrliwctrl.exePinnacle Systems InstantWrite enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basis
    Xixploreixplore.exeAdded by the SDBOT-CY TROJAN!
    Xixproxy[path to trojan]Added by the XORPIX-A TROJAN!
    Xixssoixsso.exeAdded by the AGENT.AM TROJAN! Note - example names include "XviD", "Winamp Remote", "Windows Media Player" and "Futuremark"
    Xiyelejivyujixit.exeAdded by the SDBOT.BJK WORM!
    ?IZEN/A??
    Nj2 Tray MenuHotTray.exeeFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here
    XJA Cfg Util v2jacfg2.exeAdded by the RBOT-AL WORM!
    XJA Config 32Awesome32.exeAdded by a variant of the SDBOT WORM!
    UJammerjammer.exeJammer by Agnitum - "Jammer is the last word in Internet security. It combines a user-friendly interface with very sophisticated and powerful security measures that protect your Windows system while you are surfing the web"
    XJammer2ndJammer2nd.exeAdded by the NETSKY.Z WORM!
    Xjavaremote.cmdAdded by the BANKER-EHG TROJAN!
    XJava appletjavaup.exeAdded by the SDBOT-ACF WORM!
    XJava Auto Updateujm.exeAdded by the SDBOT-ADH WORM!
    XJava Runtime Environmentjbuild.exeAdded by the DELBOT-J WORM!
    XJava Runtime Valuerunjava.exeAdded by the RBOT-DDJ WORM!
    XJava Runtimesiexplore.exeAdded by the KILLAV.B WORM! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in a WinntJavaJava folder
    XJava SofteJava32.comDetected by Kaspersky as the RBOT.ECN WORM! See here
    XJava Virtual Machinejavaw.exeAdded by a variant of the RBOT WORM!
    XJava**.exe [* = random char]Java**.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
    XJava**32.exe [* = random char]Java**32.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
    Xjava-pluginjavasctp.exeAdded by the VB.AMX TROJAN!
    XJava32 Configuration Loadermsnmesgr.exeAdded by a variant of the RBOT WORM!
    XJavaCoreJavaCore.exeDetected by Trend Micro as the DROPPER.AIO TROJAN! See here
    XJavascriptjscript.exeAdded by the DELBOT-AD WORM!
    XJavaScript Debugging ServiceJsDbgMan.exeAdded by the DERDEO.E WORM!
    XJavaScriptMsxrsMsxrs.exeDetected by Kaspersky as the BANLOAD.ERP TROJAN! See here
    XJavaUpdate0.07[filename]Added by the JUPDATE TROJAN!
    XJavaUpdateSchedjusched32.exeAdded by the CKB TROJAN!
    XJavaVMjava.exeAdded by the MYDOOM.M or MYDOOM.N or other variants of the MYDOOM WORMS! Note - not to be confused with the valid Windows "java.exe" which resides in C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP) as this resides in C:Windows or C:Winnt
    Xjawa32jawa32.exeAdded by the AGENT.BG WORM!
    XJawa322jawa32.exeAdded by a variant of the AGENT.BG trojan
    NJBJiffybar.exe"Get Paid As You surf" application
    Xjcidls[random filename]Added by a variant of the SLAPER TROJAN!
    UJessops Insert DetectInsDetect.exeJessops Insert Detect from Jessops Picture Suite
    NJet DetectionADGJDet.exeAdded with SoundBlaster Live! or Audigy soundcards for headphone autodetection
    YJetAdmin Discovery IndicatorHPJETDSC.EXEHP JetAdmin software for HP JetDirect Print Servers. HPJETDSC.EXE is the file necessary for the JetAdmin Discovery Indicator (paper airplane in the taskbar). It gets launched automatically through the registry, and remains active to control the Discovery Indicator
    Xjeteyujixit.exeAdded by the SDBOT.BRT WORM!
    Xjiahussvchqs.exeAdded by the WOWPWS-AL TROJAN!
    Xjijblezlwy.batAdded by the REDDW WORM!
    Xjkdfj94kgdftdfwinlogan.exeAdded by the ZLOB.BZ TROJAN!
    UJMB36X ConfigureJMRaidTool.exeJMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers
    UJMB36X IDE SetupJMInsIDE.exeJMB36x series IDE (or Parallel ATA) configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers
    UJob-oversigttaskmon.exeTask Monitor (on Danish language versions of Windows) - checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users, loading TaskMonitor will typically solve many, if not most, of those annoying IE scripting errors (per Symantec's Knowledgebase)
    UJobHisInitJobHisInit.exeUsed by Ricoh network printers to enable network printing from the client
    UJog ServeJogServ2.exe"Jog Dial" on a Sony Vaio laptop.  The dial can select various functions such as control audio. Needed if you use its features
    UJogServ2JogServ2.exe"Jog Dial" on a Sony Vaio laptop.  The dial can select various functions such as control audio. Needed if you use its features
    Xjohkjhsrvd.exeAdded by a variant of the SLAPER TROJAN!
    Xjohn315srrvc.exeAdded by an unidentified WORM or TROJAN!
    Xjohnj315srvc.exeAdded by variant of the MAILBOT-BI TROJAN!
    Xjohnj3155srvcc.exeAdded by variant of the MAILBOT-BI TROJAN!
    Xjohnj3cdsrvdc.exeAdded by a variant of the SLAPER TROJAN!
    Xjon315[path to trojan]Added by the MAILBOT-BI TROJAN!
    ?jotlmillenzje.exe??
    UJOYTECH USB Neo S ControllerJoytechNeoSTrayIcon.exeSystem Tray access to Joytech Neo S PC gamepad controller software
    Xjpgdiag[path to worm]Added by the STRATION-AN WORM!
    XJregJreg2b.exeBroadcastPC adware variant
    Xjucheckjucheck.exeAdded by the SCRIMGE.O WORM!
    XJufualtwinxp2.exeAdded by the SDBOT-AAB WORM!
    XJufualtsvhost.exeAdded by the SDBOT-ADJ WORM!
    NJuno_uoltrayexec.exeJuno ISP software - not required
    Njuschedjusched.exeChecks with Sun's Java updates site to see if newer Java versions are available. Visit http://java.sun.com or just run the Java Plug-In Control Panel
    Xjusched[path to trojan]Added by the BANKER-BWR TROJAN!
    Xjushed32.exejushed32.exeCoolWebSearch parasite variant - also detected as the BIZTEN-L TROJAN!
    Xjusodlsevere.exeAdded by the QQPASS.48436 TROJAN!
    UJussDropUtilityJussDrop.exeRelated to DropShots Inc. A subscription based service for family to connect, converse and share photos and videos
    Xjutsujutsu.exeAdded by the RBOT-LS WORM!
    Ujv16 PT TempFileToolTempTool.exejv16 PowerTools File Cleaner - "allows you to find obsolete and left-over temporary files"
    Ujv16PT - Privacy ProtectorTask.jvbjv16 PowerTools Privacy Protector - "allows you to protect your privacy by automatically clearing out all the unwanted history items and cookies from you computer, every time you start your computer"
    UJv16pt Network Residentjv16pt_network.exejv16 PowerTools network resident program. Only needed if you are using the program's network features
    XJvcHostjvcsvc32.exeAdded by the AGOBOT-AIU WORM!
    Xjvdnlssnfljzsshc.exeFlingstone.com adware - and its Golden Palace Casino program
    XJVM0JVM0.exeAdded by the BANLOA-AX TROJAN!
    XJVM0.12[random filename]Added by the TEADOOR-A TROJAN!
    XJVM0.14[random filename]Added by the TEADOOR-B TROJAN!
    Xjvms.exejvms.exeAdded by the ORCU.B TROJAN!
    XJW Managerjwmngr.exeAdded by the DELBOT-G WORM!
    Xjxef1104jxef1104.exeAdded by the XIPI-A WORM!
    XJXL Radiojxl.exeAdded by the RBOT-EBE WORM!
    Xjysyqm[random filename]ZenoSearch adware
    ?Jzi16jzi16.exe??
    XK2ps_full.taskK2ps_full.exeAdded by the JUNTADOR.K TROJAN!
    NK6CPU.EXEK6CPU.EXEAuthenticates CPU as K6 in system properties
    XKadoc[random filename].exeAdded by the STAPREW TROJAN!
    UKADxMainKADxMain.exeSystem Tray access to IntelliSonic Speech Enhancement - by Knowles Acoustics. Designed to render speech from a user selectable direction, while canceling interfering speech from other directions, thus minimizing the effects of environmental noise and eliminating acoustic echo feedback. Found on some Dell and Fujitsu Seimens laptops
    Xkakkak.htaAdded by the KAKWORM WORM!
    UKalibumpKalibump.exeUsed with the now unsupported Kali software for on-line gaming. This is used to automatically bump up the priority of WinProxy to GREATLY improve game speed when using a SOCKS proxy
    Xkalvsyskalv****.exe [* = random char]EliteBar adware
    Xkalvsyskalv***32.exe [* = random char]EliteBar adware
    NKana ReminderReminder.exeKana Reminder is a program which can be used to set a reminder to be triggered at a specified time
    UKaren's Once-A-Day IIPTOAD.exe"Have a job that should be run exactly once each day? Karen's Once-A-Day II is just what you need!" Scheduler that lets you specify progams, web pages and files that be run or opened automatically, the first time
    UKASPOESpamTest.exeKaspersky Anti-Spam
    XKasper AntivirusKASPERANTIVIRUS.EXEAdded by a variant of the SPYBOT WORM!
    YKaspersky Anti-HackerKAVPF.exeKaspersky Anti-Hacker firewall
    XKaspersky AntivirusKasperskyAV.exeAdded by a variant of the RBOT WORM!
    Xkaspersky32kasperskyLabs32.exeAdded by the RBOT-GOT WORM!
    XKasperskyAvkaspersky.exeAdded by the MIMAIL.T WORM! Note - this has nothing to do with the real Kaspersky AntiVirus
    XKasperskyAVEngKasperskyaveng.exeAdded by the NETSKY.V WORM!
    XKATKAT.vbsAdded by the SOAD-D WORM!
    UKatMouseKatMouse.exeKatMouse - utility to enhance the functionality of mice with a scroll wheel, offering 'universal' scrolling, etc
    Ykavavp.exeKaspersky anti-virus and AOL's Active Virus Shield (by Kaspersky) - found in either a Kaspersky or AOL sub-directory
    Xkavakavo.exeAdded by the LINEAG-GLG TROJAN!
    XKAVFOXwin1ogoin.exeAdded by the GWGHOST-M TROJAN!
    Xkavirkavir.exeDetected by Kaspersky as the ZHELATIN.XV WORM! See here
    XKAVPersonalsvchost.exeAdded by the LINEAGE-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
    YKAVPersonal50Kav.exeKaspersky Anti-Virus Personal 5.0
    XKAVPersonal90wscntfy.exeAdded by the BANKER-FZ TROJAN!
    YKavPFWKavPFW.exeKingSoft Personal Firewall
    XKavRunsWindll.exeAdded by the TRYNOMA TROJAN!
    YKavStartKAVStart.exeKingSoft Personal Firewall
    Ykavsvckavsvc.exeKaspersky antivirus
    Xkavsvc[random 6 char filename]Qoologic downloader trojan variant using random file names (examples: nzkklz.exe, rzazzi.exe, ivpaan.exe) - do not confuse with the Kaspersky antivirus startup item, as described here
    XKavSvc******.exe reg_run [* = random char]Added by the QOOLOGIC TROJAN!
    Xkavsvc[random 6 char filename]Added by the QOOLOGIC TROJAN! Uses random file names (examples: nzkklz.exe, rzazzi.exe, ivpaan.exe)
    XKAVutil[worm filename]Added by the WINTOO.B WORM!
    NKAZAAkazaa.exeKAZAA is a file-sharing program which unfortunately being ad-based includes "Cy-door" adware. Check here for information about "Cy-door" and here for a program that can remove it
    XKazaa Download Accelerator Updater (required)regsvr32 kdp****.dll [* = random char]SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    XKazaa lptt01kazaa.exeRapidBlaster variant (in a "kazaa" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name
    XKazaa ml097ekazaa.exeRapidBlaster variant (in a "kazaa" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name
    XKAZAACuf9Added by the KITRO.D (or ARGEN.A) WORM!
    Nkazaalitekazaalite.exeKazaalite is a file sharing client - not to be confused with the original Kazaa program. Unlike the original, this one does not contain any advertising or tracking mechanisms
    NKaZooMKaZooM.ExeKaZoom from Blue Haven Media - "add-on application that automatically speeds up the download process and finds the files you want with far more power than regular KaZaA searches"
    XkbAUTO.txtAdded by the BRONTK-CV WORM!
    YKB891711KB891711.exeInstalled by the Windows KB891711 critical update, see this security bulletin - this file reportedly needs to continue running in order to patch the vulnerability, at least until a more practical solution is found. There have however been reports of fatal exception errors in systems running Windows 98, and in such a case Microsoft advises to either uninstall the patch (Add/Remove Programs) or prevent it from running at startup
    YKB918547KB918547.EXEBug-fix for a Microsoft graphics rendering engine vulnerability - see here. Windows 98/Me only
    YKB926239rundll32.exe apphelp.dll, ShimFlushCacheMicrosoft KB926239 fix. Windows Media Player 10 may close unexpectedly on a Windows XP-based computer
    UKBDKBD.EXEMultimedia keyboard manager. Required if you use the multimedia keys
    UKBDKbdStub.EXEKey Watcher from HP - watches for Multimedia Keys on HP keyboards
    UKBD MediaCenterMEDIACTR.EXEMultimedia keyboard manager. Required if you use the multimedia keys
    Xkbddrv32kbddrv32.exeAdded by the CRYPTER.A TROJAN!
    Xkbddrvinfkbddrvinf.exeAdded by the CRYPTER.A TROJAN!
    NKCeasyKCeasy.exeKCeasy - a Windows peer-to-peer filesharing application which uses giFT as its 'back end' foundation. The networks currently supported are OpenFT and Gnutella
    UKClientkstatus.exeKClient Kerberos client software for Win32 systems. It provides the libraries and utilities needed to use Kerberos-based PC applications developed by Computing Services such as KWeb and NiftyTelnet
    NkdxKHost.exeVerisign Kontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops
    UKE9801DriBat32.exeKE9801 multimedia keyboard driver - required if you use the multimedia keys
    XKeenvalueKeenvalue.exeeUniverse/KeenValue adware
    UKEMailKbKEMailKb.EXEControls the buttons at the top of the Micro Innovations 650i Internet Access Keyboard. If you disable it you cannot use the buttons - like volume control or shut down
    ?Kemetkemet.exe??
    UKeNotifyKeNotify.exeToshiba utility found on their laptops. This program is responsible for the Toshiba LapTop Help 'FlashCards' utility that sits at the top of the screen giving easy access to the 'F keys' alternative functions such as Lock,Power Mode,Sleep etc
    UKerio VPN Clientkvpnclient.exeKerio VPN Client
    Xkern64dll[random filename]Added by the TARNO.J TROJAN!
    XKernal Fault Checkntosrkl.exeAdded by a variant of the SDBOT WORM!
    Xkernctl32rundll32 kctl32.dll, initializeAdded by the AGENT.AT TROJAN!
    XKerne0223Kerne0223.exeAdded by the LEGMIR-ZA TROJAN!
    XKernelbboy.exeAdded by the MUMU.B WORM!
    XKernelservices.exeAdded by the FOOZ-A TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
    Xkernelkernel.exeAdded by the MATCASH.CF TROJAN!
    XKERNEL 32SKERNEL32.comAdded by the SEMAPI-A WORM
    UKernel and Hardware Abstraction LayerKHALMNPR.EXEPart of the Logitech Setpoint software for their wired and wireless mice and trackballs. Sets the Windows mouse sensitivity to minimum. The idea is that you will use the SetPoint Control Panel to adjust your mouse sensitivity. This setting is maintained separately from the Windows setting, but is combined with the Windows setting to determine the final sensitivity. For this reason, KHALMNPR sets the Windows setting to 0 so it doesn't alter the one you set in SetPoint
    XKernel Faultsftphost.exeAdded by the RBOT.BHU WORM!
    XKernel Loaderntkrnl.exeAdded by the CERVIVEC.A WORM!
    XKernel Managerkrnlmgr.exeAdded by the JUNY.A TROJAN!
    XKernel Safe Modesmss.exeAdded by the 78CRACK-A TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
    XKernel Servicesservice32.exeAdded by the PRX-B TROJAN!
    Xkernel system daemonACTIVAT0R.exeAdded by the RANDEX.AW WORM!
    Xkernel12.exekernel12.exeAdded by an unidentified WORM or TROJAN!
    Xkernel32kern32.exeAdded by the BADTRANS.A WORM!
    XKernel32Kernel32.exeAdded by a number of VIRUSES, WORMS and TROJANS!
    Xkernel32kernel.dliAdded by the NETDEVIL.B TROJAN!
    XKernel32Kernel.dllAdded by the REDLOF.M VIRUS!
    Xkernel32kernel32.dlIAdded by the NETDEVIL.15 TROJAN!
    XKernel32krnl32.exeAdded by the EPON WORM!
    XKernel32Kernel32.winAdded by the GAGGLE.D or GAGGLE.E WORMS!
    XKernel32kernel32s.exeAdded by the SDBOT-PU TROJAN!
    Xkernel32kernel32.dll.vbsAdded by the WEKODE-A WORM!
    XKernel32svchosts.exeAdded by an unidentified WORM or TROJAN!
    Xkernel32dllguardpc.exeAdded by the FORBOT-CU WORM!
    Xkernel44.dlltaskkill /f /fi "PID ge 0" /im *Added by the VBS.LIDO WORM!
    XKernelChecksys****.exe [* = digit]Added by an unidentified TROJAN!
    XKernelCheckwinser.exeAdded by the TSPY_LMIR.SL TROJAN!
    Nkernelfaultcheckdumprep 0 -kUsed in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
    Nkernelfaultcheckdumprep 0 -uUsed in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
    XKernelFaultCheckptool32.exeAdded by the LEGMIR-BN TROJAN!
    XKernelFaultChksms.exeAdded by the DEADHAT WORM! Do not confuse with the valid "kernelfaultcheck" which runs "dumprep 0 -k" or "dumprep 0 -u"
    XKernellsystems.exeAdded by the TARNO.C TROJAN!
    XKernell32Kernell.dllAdded by the DESTINY.A TROJAN!
    XKernellAppscsrss.exeAdded by the BANCBAN-AC TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
    XKernellAppslexplore.exeAdded by the BANCBAN-BS TROJAN! Note - the executable is spelt with a lower case "L" rather than an lower or upper case "i" which is the case with Internet Explorer
    XKernellApps32smss.exeAdded by the BANCBAN-AN TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!
    XKernelRuntime[path to worm]Added by the MYTOB-JO WORM!
    XKernelRuntime[path to worm]Added by the MYTOB-JO WORM!
    XKernelwKernelw32.exeAdded by the INDOR.E WORM!
    XKernel_checkwmiprvse.exeAdded by the SONEBOT-B WORM! Note - this is not the legitimate wmiprvse.exe process which is always located in the System32wbem folder and should not normally figure in Msconfig/Startup!
    Xkeysysxp.exeAdded by the BEAGLE.AB WORM!
    Xkeysys_xp.exeAdded by the BEAGLE.AC WORM!
    Xkeywinxp.exeAdded by the BEAGLE.AG WORM!
    XKey Loggercsrss.exeAdded by the BUCHON.A WORM! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the root folder - normally C:
    NKey TextKeyText.exeKey Text 2000 from MJMSoft Design - utility to automate repetitive keyboard tasks. Available via Start -> Programs
    XKey1Rlid.exeAdded by the LIXY TROJAN!
    ?Key2serve.exe??
    Xkey2winlog.exeAdded by the BAGLEDI-AL TROJAN!
    YKeyAccesskeyacc32.exeKeyServer KeyAccess client software - "when the KeyServer program is launched, the KeyServer process becomes active so license requests from client computers can be serviced. Without KeyAccess, a keyed program cannot run, so license control is very secure"
    XKeybdcntlkeybdcntl.exeAdded by a variant of the CRYPTER.C TROJAN!
    UKeyBoardKeyboard.exeLabtec keyboard utility
    Xkeyboardkeyboard*.exe [* = number]Detected by Kaspersky as the VB.ZG TROJAN!
    Xkeyboardkybrdef_7.exeDollarRevenue adware
    Xkeyboard[path to trojan]Added by the DLOADR-AOZ TROJAN!
    UKeyboard ManagerMMKeybd.exeMultimedia keyboard manager. Required if you use the additional keys
    YKeyboard Preload CheckPreload.exeMillenium Multi-Function Keyboard driver
    Xkeyboard_enumkeyboard_enum.exeAdded by the GP TROJAN!
    UKeyMaestrokmaestro.exeMultimedia keyboard manager. Required if you use the multimedia keys
    Ukeymapkeymap.exeSystem Tray utility and background task used by games produced by Kesmai (published by Interactive Magic) and which enables you to program keys to do specific actions during the game
    Xkeymgrldrrundll32 setupapi, InstallHinfSection... keymgr3.infCoolWebSearch Oemsyspnp parasite variant
    UKeyPatrolKeyPatrol.exeKeyPatrol - key logger detector using both behavioral and pattern-matching algorithms that used to be part of PestPatrol before CA's aquisition
    Xkeyservkeyserv.exeKeyThief spyware
    UKeyspan Digital Media RemoteKDMRdmn.exeRemote control driver for Keyspan Digital Media Remote devices
    Ukeystrokekeystroke.exeQuickLaunch surveillance software. Uninstall this software unless you put it there yourself
    UKeyWalletKWallet.exe"KeyWallet is a useful and convenient desktop utility that spares you the trouble of filling in your logins, passwords and other personal data manually"
    Xkfienqmasbl.batAdded by the KIFER TROJAN!
    XKgjgrnnypbw.exeAdded by the QuickLinks/Forethought adware
    XKHATARNAK LoaderKHATARNAK.exeAdded by the AUTORUN.ACO WORM!
    Nkhookerkhooker.exeSiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required
    XKiamat Sudah Dekat_16_04ISASS.exeAdded by the PAHATIA.B WORM!
    UKICKMON.EXEKICKMON.EXEKeepItClean - utility that deletes safe to remove files, cookies, browsing history, etc. This is the scheduler - if you don't schedule clean-ups it isn't required
    UKill PopupKillPopup.exeKillPopup - pop-up stopper
    XKillAndCleanKillAndClean.exeKillAndClean spyware remover - not recommended, see here
    Xkimochiz.exekimochiz.exeAdded by the MDROP-BB TROJAN!
    NKinberlinkKinberlink.exeKinberlink network messaging. Available via Start -> Programs
    XKIT3hpprintqueue.exeAdded by the ADCLICK-DS TROJAN!
    UKK Loaderloadkk.exeKeyKey XP Professional from KeyKey.com. "Monitor Instant Messages, Chats, Emails, Web Site URLs, Passwords, Computer Programs, Start Up and Shut Down time and much more completely undetected to the user."
    XKKM Servicekkm.exeAdded by the NANPY-I WORM!
    XKL AntiFunLoveflcss.exeAdded by the FUNLOVE.4099 WORM!
    UKLogKeyspy.exeKeyLoggPro.B keystroke logger/monitoring program - remove unless you installed it yourself!
    Xklop[path to file]Added by the AGENT-WQ TROJAN!
    Xklop[random].tmpFound with Trojan.Win32.StartPage.aw. Possibly a variant of the AGENT-WQ TROJAN!
    Uklprun32dll.exePAL PC Spy - key recorder and screen capture utility which controls and monitors everything that happens on your pc and online
    Uklpexplorer.exeComSurveilSys keystroke logger/monitoring program - remove unless you installed it yourself! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is found in a SystemPALCSS subfolder
    UKM9801UMMHotKey.exeMultimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen
    Ukmw_run.exekmw_run.exeKensington MouseWorks - mouse/trackball software. Not required unles you use any special features
    Ukmw_show.exekmw_show.exeKensington MouseWorks - mouse/trackball software. Not required unles you use any special features
    XKnowledgeBase GUIwppewafaj.exeAdded by the RBOT-GRZ WORM!
    UKN_PanelAppPanelApp.exeKnowledgePanel online survey software
    NKodak Batch Transferpezdow1.exePart of "Kodak Picture Easy" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC
    UKodak EasyShare softwareEasyShare.exeSoftware bundled with Kodak digital cameras to manage the connection between the PC and the Camera. Can be started manually
    NKodak Picture Easy *.* Batch TransferPezDownload.exePart of "Kodak Picture Easy" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC. *.* represents the version
    NKodak Picture Transfer Softwarepts.exeLooks for Kodak camera connection and media insertion. Available via Start -> Programs
    NKodak Software Updaterbackweb*****.exeSoftware updater for Kodak Easyshare digital cameras
    NKODAK Software UpdaterKodak Software Updater.exeSoftware updater for Kodak Easyshare digital cameras
    YKodakCCSKodakCCS.exeKodak DC File System Driver
    UKomunikatortlen.exeTlen - a Polish language instant messaging client
    UKONICA MINOLTA magicolor 2400W STDMSTMON_S.EXEKonica Minolta Magicolor 2400W colour printer monitor
    NKonni Symbol AutostartKonniSymbol.exeGives configuration access to RagTime Solo professional business publishing software. RagTime Solo is the private user version of RagTime 5
    Nkontikikontiki.exeKontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops
    YKPDrv4XPKPDrv4XP.exeMediaKey USB Keypad Driver
    YKPFW32.EXEKPFW32.EXEKingSoft Personal Firewall
    YKPFWSvc.EXEKPFWSvc.EXEKingSoft Personal Firewall
    Xkragkrag.exeAdded by the AGENT-FOW WORM!
    UKraidmanKraidman.exe"Toshiba RAID Support is a Toshiba EasyGuard feature that uses RAID Level 1 technology to minimise downtime by protecting against data loss and ensuring quick data recovery" - for Toshiba laptops
    YKraitrazerhid.exeRazer Krait mouse driver
    UKREC32krec32.exeStarrCommander Pro Keystroke logging software
    XKRNLKernl32.exeAdded by the ZOMBY.B TROJAN!
    XKrnlcheckcsrss.exeAdded by the BOTNACHALA TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
    UKrnlmodKrnlmod.exeKeystroke logger/monitoring program - remove unless you installed it yourself!
    UKryptel Component StartKicker.exeKryptel encryption software
    Xksrlnhmzxatgso.exeAdded by the DLOADER-LI TROJAN!
    XKsrv32Ksrv32.exeAdded by the AGOBOT-PI WORM!
    XKTAX Auto Loaderktax.exeAdded by the SDBOT-MZ WORM!
    Uktchnsnkktchnsnk.exeHP program found with the Office Jet 500/600/700 series which initializes the Office Jet manager each time the computer is booted up or rebooted
    YKTPWarektp.exeRelated to KTP Ware TSR Enhancements from ELANTECH
    XKV2005word.EXEAdded by the IW TROJAN!
    Xkv3000lover.vbeAdded by the ZSYANG.B WORM!
    Xkvern16.dllregsvr32.exe kvern16.dllDailyWinner adware. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The "kvern16.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    XKvsc3Kvsc3.exeAdded by the PWS-ANM TROJAN!
    XKV_HOSTcxjx.exeAdded by the LEGMIR-BB TROJAN!
    Xkw3eef76rundll32.exe kw3eef76.dll, EnableRunDLL32LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "kw3eef76.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    NkX Mixerkxmixer.exeProvides Mixer and Control functionality to KxProject Audio driver for EMU10k based soundcards
    UKX509kx509_kfwk5.exeKerberos Secure Authentication for Windows
    ?KYE_Showiconshwicon.exeCard reader for memory cards from digital cameras. Is it required?
    XKYK Control SettingsKYSVCXD.EXEAdded by a variant of the RBOT WORM!
    XKYM Control Settingsphqghum.exeAdded by the RBOT.BQD WORM!
    XL0adersfaxneti.exeAdded by a variant of the SDBOT TROJAN!
    Xl44sys**freecellAdded by the VBS.LIDO WORM - where ** is a number between 1 and 12
    Xl44sys**iexploreAdded by the VBS.LIDO WORM - where ** is a number between 65 and 76
    Xl44sys**winmineAdded by the VBS.LIDO WORM - where ** is a number between 33 and 44
    XL4r1$$aL4r1$$a.pifAdded by the ASSIRAL-C WORM!
    YLachesisrazerhid.exeRazer Lachesis mouse driver
    ULaCie BackupLaCieBackup.exeLaCie '1-Click' backup software for their range of mobile hard drives
    Ulaimaimlite.exe"AIM Lite is a reference application for testing some new client technology developed here at AOL?, with the goal of being a simple, fun, light IM client"
    XlaltinL90112201.Stub.exeDelfin Media Viewer adware related
    XLAN Driverlandriver32.exeAdded by the RBOT.BT WORM!
    Xlanbruplanbrup.exeSafeSurfing adware
    ULANDeskInventoryClientLDIScn32.exeLANDesk? Management Suite software component
    ULanguageMonitorOplmsb01.exeOKI Printer language support monitor
    ?LanguageShortcutLanguage.exeLanguage setting for Cyberlink's PowerDVD?
    XLanGuardlanguard.exeAdware downloader - also detected as the SECONDT-C TROJAN!
    XLanGuard[path to trojan]Added by the DLOADER-VO TROJAN!
    Xlanmanwrk.exelanmanwrk.exeAdded by the AGENT.AIA TROJAN!
    ULANMessage ProLANMES~1.exeLANMessage Pro - "a powerful tool for communicating with other people on your office/home network"
    ULanSpeed2LanSpeed2.exeMonitors any traffic that is using a LAN adapter (Ethernet or Token ring network card)
    ?LanzarL2007[path] setup.exe??
    ULaoKeyLaoKey.exeLao Script for Windows (LSWin) is an extension to the Windows operating system to allow Lao language to be used with many different Windows-based applications
    ULapLink schedulerLlsched.exeUtility that automatically performs file transfers as unattended background operations
    XLarLlass.exeAdded by the INOR-A TROJAN!
    Xlar[trojan filename]Added by the ROXY.C TROJAN!
    XLARISSA ANTI VIRUSLARISSA_ANTI_VIRUS.exeAdded by the KLASSIR TROJAN!
    ?Lasbewat.exe??
    XLasErmaErmasys32.exeAdded by the LERMA-A WORM!
    XLAsIAf32RePEAtLD.exeAdded by the REPEATLD WORM!
    Xlasselasse.exeAdded by the NTOS TROJAN!
    YLASTinstN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
    ?Laterlater.exe??
    ULaunAppLaunApp.exePart of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610
    ?Launcglauncg.exe??
    ULaunch Ai BoosterOverClk.exeASUS Ai Booster is an application that allows you to overclock the CPU either manually or automatically without the hassle of entering the BIOS Setup
    NLaunch Context 5.0Launch.exeContext - electronic dictionary
    ULaunch LCDMonLCDMon.exeLogitech LCD G-Series software driver
    NLaunch LCDMonLCDMon.exeDriver/utility for Logitech G-Series gaming keyboards and mice
    ULaunch LGDCoreLGDCore.exeDriver/utility for Logitech G-Series gaming keyboards and mice
    XLaunch Norton AntiVirus 2000jorgf.exeAdded by the RBOT-AUI WORM!
    NLaunch YahooPOPs! at Windows startupYAHOOPOPS.EXEYahooPOPs - enables free POP3/SMTP access to Yahoo! Mail through a service on localhost that emulates the web interface. Available via Start -> Programs
    ULaunchApLaunchAp.exeProgrammable keys on Acer, Fujitsu and other laptops
    ULaunchAppAlaunch.exeAcer Launch tool utility on laptops
    ULaunchboardlnchbrd.exe"LaunchBoard software from Darwin turns your keyboard into a remote control for the Internet and your computer! With LaunchBoard 2.0, you can customize up to 38 keys on your PC keyboard to instantly launch Web Sites, start applications, perform custom macros, handle Windows shortcuts, store passwords, and perform loads of other customizable functions"
    XLauncherlauncher.exeSpyware component related to DownloadWare and found in Program FilesKFH
    NLauncherrelaunch.exeAudio Applications Launcher for the Philips Rythmic Edge soundcard (the Philips Rhythmic Edge is the same as the Thunderbird PCI soundcard - see TBtray). Available via Start -> Programs
    ULauncherlauncher.exePC Angel recovery program from SoftThinks. Located in a "SMINST" sub-folder of the Windows or Winnt directory
    ?LaunchListLaunchList2.exePart of Pinnacle Studio video editing suite. What does it do and is it required?
    XLavasoft Ad-AwareAd-Aware.exeAdded by the RBOT-SO WORM! Note - this is not the popular Ad-aware spware/adware removal tool
    ULavasoft AdwatchAd-watch.exePart of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system
    Xlayersldmhostplsrvc.exeAdded by a variant of the SDBOT WORM!
    XLazKernn.exeAdded by the BANCOS-LN WORM!
    XLBTWiz.exeLBTWiz.exeAdded by the SDBOT-DHY WORM!
    XLcassLcass.exeAdded by the SILLYFDC-W WORM!
    ULCD SmartieLCDSmartie.exe"LCD Smartie is software for Windows that you can use to show lots of different types of information on your LCD/VFD." Typically used by the PC modding community to display statistics such as CPU temp, fan/cooler speed, etc on an LCD display
    ULCDCLCDC.exeLCDC is an application that displays various information on your LCD or VFD screen. The number of things that LCDC can do is expandable by Plugins
    YLCDMonLCDMon.exeDriver/utility for Logitech G-Series gaming keyboards and mice
    YLCDPlayerLCDPlyer.exeRelated to SuperAdBlocker
    Nlcfeplcfep.exeTivoli 'TME' System Tray icon - "'lcfep' is the program that displays statistics about the Endpoint. Apparently stopping/removing this process has no impact on the Endpoint itself which will continue to function normally"
    ?LCIDConfiglcidchng.exe??
    ULClocklclock.exeLClock is a program that makes the Windows' clock look like a Windows Longhorn Clock
    Xlcvgalcvga.exeAdded by the HOSTOL-A TROJAN!
    Xldld.exeCoolWebSearch Tooncomics parasite affiliate variant - redirects to fastwebfinder.com
    NLDMbackweb-8876480.exeInstalled with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech
    NLDMldmconf.exeInstalled with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech
    NLDMLogitechDesktopMessenger.exeInstalled with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech
    Xldriverldriver.exeAdded by the CHORUS-A TROJAN! Searchforfree browser hijacker
    ULED TRAYLEDTRAY.EXEInstalls a USB compact flash card reader or drive on start-up. The device is distributed by Microtech and is made by a company called SnapShot. Required if you want the reader to work
    UledpointerCNYHKey.exeChicony Electronics Multimedia Keyboard Hotkey Driver
    NLeechGetLeechGet.exeLeechGet download manager
    Xleemanleeman.exeAdded by the COSIAM-D TROJAN!
    XLEMSRVlemsrv.exeAdded by the IRCBOT-TC TROJAN!
    XLetsSearchLetsSearch.exeBrowserAid/BrowserPal foistware
    XLetum[path to worm]Added by the LETUM.A WORM!
    ULexmark 1200 Serieslxczbmgr.exe"Lexmark Scan & Copy Control Program" for the Lexmark 1200 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc
    ULexmark 2200 Serieslxbvbmgr.exe"Lexmark Scan & Copy Control Program" for the Lexmark 2200 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc
    ULexmark 3100 Serieslxbrbmgr.exe"Lexmark Scan & Copy Control Program" for the Lexmark 3100 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc
    ULexmark 4200 Serieslxbmbmgr.exe"Lexmark Scan & Copy Control Program" for the Lexmark 4200 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc
    ULexmark 5200 serieslxbtbmgr.exe"Lexmark Scan & Copy Control Program" for the Lexmark 5200 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc
    ULexmark 5400 Series Fax Serverfm3032.exeFaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software
    XLexmark Printlexmark.exeAdded by a variant of the SPYBOT WORM! See here
    ULexmark X1100 Serieslxbkbmgr.exe"Lexmark Scan & Copy Control Program" for the Lexmark X1100 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc
    ULexmark X5100 Serieslxbabmgr.exe"Lexmark Scan & Copy Control Program" for the Lexmark X5100 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc
    ULexmark X6100 Serieslxbfbmgr.exe"Lexmark Scan & Copy Control Program" for the Lexmark X6100 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc
    ULexmark X63 Button ManagerAcBtnMgr_X63.exe"Lexmark Scan & Copy Control Program" for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc
    ULexmark X63 Button MonitorACMonitor_X63.exeButton monitor for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Works in conjuction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X63.exe"
    ULexmark X73 Button ManagerAcBtnMgr_X73.exe"Lexmark Scan & Copy Control Program" for the Lexmark X73 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc
    ULexmark X73 Button MonitorACMonitor_X73.exeButton monitor for the Lexmark X73 all-in-one multifunction printer/copier/scanner. Works in conjuction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X73.exe"
    ULexmark X74-X75lxbbbmgr.exe"Lexmark Scan & Copy Control Program" for the Lexmark X74-X75 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc
    ULexmark X83 Button ManagerAcBtnMgr_X83.exe"Lexmark Scan & Copy Control Program" for the Lexmark X83 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc
    ULexmark X83 Button MonitorACMonitor_X83.exeButton monitor for the Lexmark X83 all-in-one multifunction printer/copier/scanner. Works in conjuction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X83.exe"
    ULexmark X84-X85 Button ManagerAcBtnMgr_X83-X85.exe"Lexmark Scan & Copy Control Program" for the Lexmark X84-X85 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc
    ULexmark X84-X85 Button MonitorACMonitor_X85-X85.exeButton monitor for the Lexmark X85-X85 all-in-one multifunction printer/copier/scanner. Works in conjuction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X85-X85.exe"
    NLexmarkPrinTrayprintray.exeLexmark Printer icon in the System Tray for quick access. Not required - uncheck via Printer configuration rather than MSCONFIG. Can also be listed as PrinTray
    XLexmark_X79-55lsasss.exeAdded by the ZONEBAC TROJAN!
    Xlexplorelexplore.exeAdded by the BROPIA WORM! Note - the executable is spelt with a lower case "L" rather than an lower or upper case "i" which is the case with Internet Explorer
    Nlexppslexpps.exeFor Lexmark printers. From Lexmark: "This enables bi-directional printing over a peer to peer network. If the printer is connected directly to your PC, the file is not used, (or should not be used) at all". It is known that firewalls can however alert you to "lexpps.exe" requesting server privileges
    ULexStartlexstart.exeLexmark printer software may add Lexstart.exe in the startup folder to handle print commands that you send to the printer. Sometimes required for the printer to work correctly - not in the case of a Lexmark Z42 for instance
    XLfhLfh.exeAdded by the ZAURGA-A TROJAN!
    ULfsndmnglfsndmng.exeLightningFAX Enterprise Fax Server - "puts faxing at the fingertips of networked enterprise users. It enables rapid, secure sending and Direct-To-Desktop Delivery of mission-critical documents"
    ULGDCoreLGDCore.exeDriver/utility for Logitech G-Series gaming keyboards and mice
    Xlgmlgm.exeAdded by the ACID-F WORM!
    ULGODDFUfwupdate.exeAuto firmware update program for LG Electronics CD-ROM/DVD writer
    ULgWDskTpLgWDskTp.exeLogitech Wireless Desktop mouse and keyboard software. There is an icon for this program on the taskbar next to the clock
    Nlhttsengrundll32.exe ..lhttseng.inf, RemoveCabinetLeft over after installation of the British English version of the Lernout & Hauspie Text To Speech (TTS) Engine
    Xli-multi****li-multi****.exeAdult web-dialler - **** is random
    Xli-rcash00001vldial.exeAdded by the Vl TROJAN!
    Xli-speed****dlres.exeAdult web-dialler - **** is random
    Xli-thund****li-thund****.exeAdult web-dialler - **** is random
    Xli-vita****li-vita****.exeAdult web-dialler - **** is random
    Xli01f948rundll32.exe li01f948.dll, EnableRunDLL32LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "li01f948.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    NLicCrtlrunservice.exePart of the eLicense Copy Protection scheme employed by some software and games. When this service is not running, the eLicense wrapper is unable to extract and execute the program
    ULicCtrlrundll32.exe MMFS.DLL, ServicePart of the eLicense Copy Protection scheme employed by some software and games. When this service is not running, the eLicense wrapper is unable to extract and execute the program. Note that the "MMFS.DLL" file is located in the Winnt or Windows folder
    XLicense Managerlicense_manager.exeMediaPipe peer-to-peer file swapping program also reported as a hijacker
    Xlichlich.exeAdded by the QLOWZON-BN TROJAN!
    ULidPolicypwrschem.exeA utility for configuring certain HP notebook models to enter Standby mode when the lid is closed only when running on battery
    XLife FireWall Update1FireWall-Update1.exeAdded by the RBOT-ARS WORM!
    ?LifeCamLifeExp.exeRelated to Microsoft's LifeCam series of webcams. What does it do and is it required?
    ULifeChatLifeChat.exeSupport software for Microsoft's "LifeChat" headsets - which are optimized for use with Windows Live Messenger
    NLifeDrive ManagerLifeDriveMgr.exeKeeps the Palm LifeDrive Manager utility in the systray. Shortcut available via Start -> Programs
    ULifeDrive? ManagerLifeDriveMgrTray.exeSystem Tray utility for the Palm LifeDrive Mobile Manager
    NLifeScape Media DetectorPicasaMediaDetector.exeMedia detector for Picasa's automatic photo organizer
    Xlifyyujixit.exeAdded by a variant of the SDBOT WORM!
    ULightning DownloadLightning.exeLightning Download download manager. Can be launched manually, but will need to start up if you want it to "catch clicks" off Internet Explorer
    XLimewireLimeWire.exeAdded by the RBOT-AGH WORM!
    NLimeWire On StartupLimeWire.exeLimeWire - Peer to Peer (P2P) file-sharing client. Note - as with all P2P sharing programs they are susceptible to various forms of malware
    NLimeWire x.xLimeWire.exeLimeWire - Peer to Peer (P2P) file-sharing client. x.x represents the version number. Note - as with all P2P sharing programs they are susceptible to various forms of malware
    Xlimewirepro.exelimewirepro.exeAdded by the IRCBOT-WA WORM!
    XLimpetexplorer16.exeAdded by the RBOT-AJD WORM!
    NLine Speed Meter V3.0LineSpeedMeter.exeLineSpeedMeter - detect the download and upload speed of your internet connection
    ULingvo LauncherLvagent.exeABBYY Lingvo Electronic Dictionaries
    ULingvoTrainingTutor.exeABBYY Lingvo Electronic Dictionaries
    XLinkerLinkMaker.exeLinks adware
    Xlinkslinks.exeAdded by the LOWZONE-BI TROJAN!
    NLinkstslinksts.exeTray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards, such as MRi). This icon enables you to monitor or configure your ISDN card. Once you have configured your ISDN card correctly, you will never need to use this icon
    XLinkstslinksts.exeTray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards, such as MRi). This icon enables you to monitor or configure your ISDN card. Once you have configured your ISDN card correctly, you will never need to use this icon
    XLinksys Modem Driverslinksys.exeAdded by the IRCBOT.VD WORM!
    Xlinkyuulinkuyy.exeAdded by the DLOADER.MC TROJAN!
    XLinuxLinux.vbsAdded by the LOVELETTER.AS VIRUS!
    ULiquidViewlviewj.exe"Liquid View lets you increase the legibility of the Microsoft Windows interface regardless of your display's native resolution. The software lets you increase the size of items that are hard to read on your monitor"
    XLisaLisa.exeAdded by the SCOM-D premium rate adult content dialler
    XList checker 32 BITlist32.exeAdded by the RBOT-AHO WORM!
    XLitebot[path to trojan]Added by the LITEBOT-A TROJAN!
    NLIULIU.exeLogitech Internet Update. Used to update drivers/software for Logitech's Wingman, QuickCam, etc devices. Reports claim it doesn't work very well and you can manually update the files anyway
    NLIURubicon.exeLogitech Internet Update. Used to update drivers/software for Logitech's Wingman, QuickCam, etc devices. Reports claim it doesn't work very well and you can manually update the files anyway
    NLive MenuDllcmd32.exeeFax Send button for eFax Messenger Plus. Available via Start -> Programs Disabling instructions available here
    XLive Messangerlivemsgr.exeDetected by Kaspersky as the RBOT.BXX WORM! See here
    XLive update monitorsrvany32.exeAdded by the AGOBOT.AFM WORM!
    XLive-Helplmns.exeAdded by the RBOT-GHE WORM!
    NLiveMonitorLMonitor.exeMSI Live Update - auto-detects and suggests the latest BIOS/Driver/Utilities information
    NLiveNoteLivenote.exeAsus graphics card driver live update feature
    XLiveSexCamsLiveSexCams.exePremium rate adult content dialler
    ULiveUpdateLiveUpdate.exeWeb-update utility as used by various types of software - see here
    XLiveUpdate[Windows username]05.exeAdded by the LINEAGE TROJAN!
    XLiveUpdatesmss.exeAdded by the VB.BAU TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "isas" subfolder of the Winnt or Windows folder
    NLiveUpdateCopyer.exeSamsung PC Studio is a Windows-based PC program package that you can use easily to manage personal data and multimedia files by connecting a Samsung Electronics Mobile phone (GSM/GPRS/UMTS) to your PC. You can launch the update manually - see the instructions here for example
    XLiveUpdate32services.exeAdded by the VB.BAU TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "isas" subfolder of the Winnt or Windows folder
    XLivreDibane.batAdded by the BANEDI VIRUS!
    XLjxrundll32.exeAdded by the LINEAG-ABD TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). This file is located in the "inf" sub-folder
    Xlk3h1[path to file]Added by the MOSUCK-G TROJAN!
    ?LLMODCL2rundll.exe setupx.dll, InstallHinfSection ..LLMODCL2.INF??
    Xllsassllsass.exeAdded by the PROXY-GG TROJAN! Note - this malware actually changes the default value data of the registry "Run" key in order to force Windows to launch it at boot. Name field may be empty
    NLM StatusLMSTATUS.EXEXerox WorkCenter XE - language monitor status application
    XLMA Managerlmamanager.exeAdded by the TILEBOT-AD WORM!
    ULManagerQtZgAcer.EXEAcer Launch Manager - on Acer laptops it allows users to configure shortcut keys and to set the operating state of the WLAN module and the (optional) Bluetooth radio
    ULManagerQtZpAcer.exeAcer Launch Manager - on Acer laptops it allows users to configure shortcut keys and to set the operating state of the WLAN module and the (optional) Bluetooth radio
    ULManagerHotkeyApp.exeAcer Launch Manager - on Acer laptops it allows users to configure shortcut keys and to set the operating state of the WLAN module and the (optional) Bluetooth radio
    ULManagerQtaET2S.EXEAcer Launch Manager - on Acer laptops, provides configurability for the special keys on their range of multimedia keyboards
    XlMAPllMAPl.exeAdded by the AGOBOT-RE WORM!
    ULMgrOSDOSDCtrl.exeOSD (on-screen-display) utility - part of Acer Launch Manager. Gives you control to customize the monitor to your liking...from sound, brightness, contrast, horizontal and vertical positions, phase, pixel clock, color and language
    NLMonitorLMonitor.exeMSI Live Update - auto-detects and suggests the latest BIOS/Driver/Utilities information
    ?lmpdpsrvlmpdpsrv.exeRelated to a Lexmark printer/scanner. Printer sharing server? Is it required?
    Xlmrtlmrt.exeUnidentified adware
    NLMSTATUSLMSTATUS.EXEXerox WorkCenter XE - language monitor status application
    YLMSXXDLMSXXD.exeDriver for Xerox XD series printer/copiers
    XlmuLMU.exeDetected by Kaspersky as the AGENT.BG TROJAN!
    Xlnternet ExplorerAMSNDMGR.EXEAdded by the KWBOT.R WORM! Note that the "l" is a lower case "L" and not an upper case "I"
    Xlnternet UpdatelExplore.exeAdded by the RBOT-GRH WORM! Note - the executable is spelt with a lower case "L" rather than an lower or upper case "i" which is the case with Internet Explorer
    Xlnwin.exelnwin.exeAdded by the DLOADR-ATC TROJAN!
    Xloadmdm.exeAdded by the BINGHE TROJAN!
    Xloadmsgsr32.exeAdded by the SDBOT-QR WORM!
    Xload[path to worm]Added by the KELVIR.AI WORM!
    XLoadMyGame.exeAdded by the LAMEYEAR-A WORM!
    Xload_Kerne1.exeAdded by the LINEAGE-AN TROJAN!
    XloadInternat.exeAdded by the WOWCRAFT TROJAN!
    Xloadrundll32.exeAdded by the WOWCRAFT TROJAN!
    Xloadsvhost32.exeAdded by the WOWCRAFT TROJAN!
    Xloadsvchsot.exeAdded by the GWGHOST-O TROJAN!
    Xloadexplorer.exeAdded by the LINEAGE-OZ TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    XloadKerne121.exeAdded by the LINEAGE-ON TROJAN!
    XloadKerne1211.exeAdded by the LINEAGE-DY TROJAN!
    Xloadrundl132.exeAdded by the LOOKED-CK WORM!
    Xloadctftpscr32.exeAdded by the AGENT-FPN TROJAN!
    XLoadwin32.exeAdded by the RUBBLE-A WORM!
    XLoad ServiceSvHost.exeAdded by the PESIN-D WORM!
    ULOAD WBLOADWB.EXEPart of Stardock's WindowBlinds custom desktop program. "WindowBlinds is the first utility of its kind. It extends Win98/NT/2K/XP to have a fully skinnable user interface. You can change the style of title bars, buttons, toolbars and much more". If you use it - keep it if not then uninstall it
    XLoad-GuardWscript.exe LGuarg.exe.vbsAdded by the YENO.B and YENO.C WORMS! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "LGuarg.exe.vbs" file is located in the Winnt or Windows folder
    XLOAD32Lorena.exeAdded by the MAPSON.C WORM!
    Xload32load32.exeAdded by the NIBU, BAMBO TROJANS and DUMARU WORM!
    Xload32l32x.exeAdded by the DUMARU.Z or DUMARU.Y or DUMARU.AD WORM!
    Xload321111a.exeAdded by the DUMARU.AH WORM!
    Xload32swchost.exeAdded by the TURTA.A WORM!
    Xload32netda.exeAdded by the NIBU.E TROJAN!
    Xload32winldra.exeAdded by the BACKDOOR.NIBU.J or DUMARU-BI TROJANS! Note - also known as Srv.SSA-KeyLogger by Sunbelt Software which has developed a free removal tool for this keylogger
    Nload=adw30.exeAfter Dark for Windows - screen saver program. Popular before screen savers were integrated into Win95
    Uload=asistat.exeStatus monitor for an NEC SuperScript printer
    ?load=cfgsys32.exe??
    Uload=esspk.exeSpeakerphone capability through a soundcard for an ESS modem
    Yload=hotkey.exeSolo 5300 display driver for Win2K on some Gateway laptops
    Nload=HPWHRC.EXELoads the Status Window software for the HP Laserjet printers
    ?load=WPSLOAD.EXEWindows printing system that comes with the setup for Canon BJC series on the manufacturer's disk
    Nload=vi_grm.exeMonitor drivers for Trio2x/3x based video cards - displays control panel for quick access to display settings
    ?load=WINOSCFG.EXECould it be something to do with configuring Windows on a new PC from an OEM supplier?
    Yload=wpshrc.exeRequired to prevent configuration errors on a Compaq LBP-660 and LBP-460 parallel port laser printers (and maybe others)
    Yload=Bfrecv.exeBitware modem driver
    Xload=msater.exeAdded by the RETSAM TROJAN!
    Xload=shambl3r.exeAdded by the REMABL WORM!
    Xload=Spoolsv.exeAdded by the CIADOOR.B TROJAN! Note - "Spoolsv.exe" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file
    ?Load=wtfeat.exeAssociated with the Wintab Digitizer
    Yload=AICLIENT.EXEAsset Insight from Tangram - asset managing software. Required if an organisation is running a centrally administered asset management system
    Xload=hint.exeAdded by the ATAK WORM!
    Xload=win32exec.exeAdded by the BITTER WORM!
    Xload=a1g.exeAdded by the ATAK.B WORM!
    Xload=dapdll.exeAdded by the ATAK.E WORM!
    Xload=svhost32.exeAdded by the LINEAGE-AB TROJAN!
    Yload=01comm32.exeRelated to Elsa CommPro (Communicate Pro) access software for Microlink modems - this software contains answering machine and fax functions, plus a terminal program, a WWW-browser launch function, Internet telephony, and address management. Required if you use those
    Xload=inetinfo.exeAdded by the PROXY-GG TROJAN!
    Xload=Kerne14.exeAdded by the LINEAGE-BA TROJAN!
    XLoadab1explorer.exeAdded by the LINEAGE-AJ TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the Program Files folder
    YLoadBlackDblackd.exeThis is the "intrusion detection system" of the BlackICE PC Protection (was Defender) firewall which loads independently of the "user interface" (BlackICE Utility)
    ULoadBtnHndBtnHnd.exeFujitsu Siemens Lifebook laptops have some buttons on the case that can be programmed to execute specified programs (like hotkeys). The buttons can also be used as a combination lock input
    XLoadDBackUpBcTool.exeAdded by the GIBE WORM!
    Xloaddllloaddll.exeWinvest spyware
    ?LoadDvpApi9xDVPAPI9X.exePart of Command AntiVirus for Windows 95/98/Me. Is it needed?
    Xloaderloader.exeHomepage hijacker, redirecting to coolwwwsearch.com. Downloader for iedll.exe
    XloaderWMPLAYER.EXEUnknown baddie - WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup
    Xloader32 sys*****.exe [***** = random digit]Added by the DOMCOM TROJAN!
    Xloader32Loader32.exeAdded by an unidentified TROJAN!
    XLoadersHeIp.exeAdded by the SDBOT-ADB WORM!
    Xloadfaxloadfax.exeAdded by the WINFLUX-C TROJAN!
    XLoadFontsLoadFonts.vbsHomepage hijacker that changes your homepage to an adult content site
    XLoadFontsTahoma.vbsHomepage hijacker that changes your homepage to an adult content site
    ULoadFujitsuQuickTouchQuickTouch.exeMaps the keys on a Fujitsu Siemens Lifebook application panel to various programs and functions
    XLoadGolfCoursesLoadGolfCourses.exePlayMiniGolf.com foistware - stealth installed!
    XLoadHTMLrundll32.exe mshtmpre.dll, MShtmpreMshtmpre adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "mshtmpre.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    XLoadingAgentZipLoader32.exeAdded by the OBLIVION TROJAN! This executable is one of the most common but there are more
    XLoadingAgentmsload32.exeAdded by the OBLIVION TROJAN! This executable is one of the most common but there are more
    XLoadManagermsload.exeAdded by the OPASERV.T WORM!
    XloadMecq0explorer.exeAdded by the MUMUBOY.C TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the Program Files folder
    XloadMecq3rundll32.exeAdded by the LEGMIR-AS TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). This file is located in the Root folder (C:), (D:), etc
    XloadMect1explorer.exeAdded by the LINEAGE-L TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the Program Files folder
    XloadMefsrundll32.exeAdded by the LEGMIR-JB TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). This file is located in the Windowsinf or Winntinf folder
    XloadMefssmss32.exeAdded by the FLOOD-EL TROJAN!
    NLoadMSvcmmmsvcmm32.exeAuto-update for Movielink - internet movie rental System Tray access
    XLoadOrderVerification[random filename]Added by the TRON.A TROJAN!
    ULoadout Managernost_LM.exeManager for the Belkin Nostromo n50 SpeedPad game controller - see here
    XLoadPFWwmimgr.exeAdded by the QEDS-B WORM!
    XLoadPowerProfileASDAPI.EXEAdded by the CABRO TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll
    ULoadPowerProfileRundll32.exe powrprof.dllPower management specifics such as monitor shut-off, system standby, etc. Associated with power management and is listed twice - see here. Loads your selected power scheme. May not be required - depends upon whether you modify the default Control Panel -> Power Options settings
    XLoadPowerProfileRundll.exe powerprof.dllAdded by the LOXOSCAM TROJAN! Note - do not confuse with the valid LoadPowerProfile entry! Notice that the infected version uses "Rundll.exe" whereas the uninfected version uses "Rundll32.exe"
    XLoadPowerProfilerundl.exeAdded by the TOFAZZOL TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll
    XLoadPowerProfileRundll32.exeAdded by the MIROOT WORM! Note - do not confuse with the valid LoadPowerProfile entry which has "powrprof.dll" appended to the command/data line
    XLoadPowerSchemerundll32.exe powerprof.dll CheckPowerProfileUlubione adult content dialer. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
    ULoadQMloadqm.exeInstalled with MSN Explorer and loads the MSN Queue Manager. Required to enable the WU AutoUpdate feature. Note that disabling this can sometimes prevent internet sharing working on Win2K Pro SP2. Reports also suggest that removing it will re-enable internet access - hence the "users choice" recommendation. If you have problems leave it, otherwise I recommend you disable it
    Xloads.exeloads.exeMediaMotor adware
    Xloads.exemedload.exeMedload adware
    Xloads.exesuploads.exeAdded by the AGENT-BZ TROJAN!
    XLoadServiceRest In PeaceAdded by the KANGAROO-A WORM!
    XLoadServiceMaaf, tempatmu bukan di sinAdded by the KAGEN-A TROJAN!
    XLoadServiceVirusAdded by the CAGER.A WORM!
    XLoadSIPSrundll32.exe SIPSPI32.dll, SIPSPI32123Mania adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "SIPSPI32.dll" file is found in the System folder
    ?LoadWatcherTest.exeReportedly part of a webcam surveillance program that's supposed to test SMTP dialling in the event of an alert? Is this correct?
    XLoadWatcherwatcher.exeWatcher spyware
    Xloadwinwinset.exeAdded by the QQPASS-I TROJAN!
    Xloadwinwinsys.exeAdded by the QQPASS-J TROJAN!
    XLoadWindowsFile[filename]Added by the DELF.B TROJAN! where [filename] is the infected file
    XLocal Area NetworkOpenGL.exeAdded by a variant of the RBOT WORM!
    XLocal Authority Servicelsass.exeAdded by the AMRKTMAN-C TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
    XLocal Internet ConnectionLIC.exeAdded by the SDBOT-YA WORM!
    XLOCAL INTERNET WEB DRIVERS FOR WIN32phqghume.exeAdded by a variant of the RBOT WORM!
    XLocal Pagehttp://find.naupoint.comNaupoint browser hijacker
    XLocal runole servicesrvc32.exeAdded by the SMALL-DP TROJAN!
    XLocal Security Authority Servcelssas.exeAdded by the POEBOT-T WORM!
    XLocal Security Authority Servicelssas.exeAdded by the POEBOT-J WORM!
    XLocal Security Authority ServiceIsass.exeAdded by the LINKBOT.M WORM!
    XLocal ServiceIntenat.exeAdded by the NUCLEAR-J TROJAN!
    XLocal Serviceservices.exeAdded by the P2PWORM-T WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "Cursors" subfolder of the Windows or Winnt folder
    XLocal-Settings-of-[User Name][User Name].exeAdded by the GAVGENT.A WORM!
    ULocalProxyproxy4free.exe"ProxyTools is a package of Perl network utilities designed mainly to assist those whose Internet access is censored, unreliable, or otherwise damaged. Uncensored access is provided to any outside service required (Usenet News, Web browsing, IRC, Socks etc.). Setup requires installation of Perl and some modules"
    XLocalSystemsvchost.exeEHU adware. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
    XLocator Service[filename]Added by the AGOBOT-KY TROJAN!
    ULock My PClockpc.exeLock My PC - a tool for quick computer locking when you leave it unattended. It shows a lock screen, disables Windows hot keys and mouse
    Xlogglogo_1.exeAdded by the PWFUZZ-A WORM!
    XLogical Disk Detectionmrisvc.exeDetected by Kaspersky as the IRCBOT.AOW TROJAN! See here
    NLogiciel de transfert d'images KODAKpts.exeLooks for Kodak camera connection and media insertion. Available via Start -> Programs
    ULoginwinlog.exeSalfeld Child Control - parental control software
    Xlogin[path to trojan]Added by the HOTWORD-A TROJAN!
    XLoginLogin.exeAdded by the BANCBAN-AH TROJAN!
    XLoginlala.exeAdded by the BUGSPR-A TROJAN!
    XLogin Screen Saverlogin.scrAdded by the RBOT-AVN WORM!
    XLogin Service[path to file]Added by the MIGMAF TROJAN!
    XLoginPassportLgnpsp32.exeAdded by the REDIST.C WORM!
    Xloginui32loginui32.exeAdded by the LONGNU.A TROJAN!
    XLogitechLogitech.exeAdded by the RBOT.BJH WORM!
    XLogitech CameraSoundcane.exeAdded by the SDBOT.MUC WORM!
    XLogitech DesktopApPache.exeAdded by the RBOT-YP WORM!
    XLogitech DesktopIPCONN.EXEAdded by the SDBOT-WE WORM!
    XLogitech Desktop Controllerwrcam.exeAdded by a variant of the RBOT WORM!
    NLogitech Desktop Messengerbackweb-8876480.exeInstalled with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech
    NLogitech Desktop Messengerldmconf.exeInstalled with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech
    NLogitech Desktop MessengerLogitechDesktopMessenger.exeInstalled with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech
    ULogitech Hardware Abstraction LayerKhalmnpr.exePart of the Logitech Setpoint software for their wired and wireless mice and trackballs. Sets the Windows mouse sensitivity to minimum. The idea is that you will use the SetPoint Control Panel to adjust your mouse sensitivity. This setting is maintained separately from the Windows setting, but is combined with the Windows setting to determine the final sensitivity. For this reason, KHALMNPR sets the Windows setting to 0 so it doesn't alter the one you set in SetPoint
    ULogitech Harmony RemoteHarmonyClient.exeLogitech Harmony advanced universal remote
    ULogitech Harmony Remote Software 7HARMON~1.EXELogitech Harmony Advanced Universal Remote controller software
    ULogitech SetPointKEM.exeKeyboard and mouse drivers and utilities for Logitech's latest products - supersedes iTouch and MouseWare on their older products. Required if you use special features such as multimedia keys
    ULogitech SetPointKHALMNPR.EXEPart of the Logitech Setpoint software for their wired and wireless mice and trackballs. Sets the Windows mouse sensitivity to minimum. The idea is that you will use the SetPoint Control Panel to adjust your mouse sensitivity. This setting is maintained separately from the Windows setting, but is combined with the Windows setting to determine the final sensitivity. For this reason, KHALMNPR sets the Windows setting to 0 so it doesn't alter the one you set in SetPoint
    ULogitech SetPointSetpoint.exeLogitech SetPoint Event Manager for their range of mice and keyboards. Required if you want to use the advanced features of these devices and is located in the LogitechSetpoint sub-folder of Program Files
    ULogitech UtilityLogi_MwX.exeLogitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as "SmartMove". If you disable it and find you don't need it leave it disabled
    NLogitech Wakeuplgwakeup.exeLoads at startup and monitors the scanner. When a document is inserted in the scanner the wakeup program feeds the document a fraction of a inch into the scanner and then it launches the control center software. From the control center you can select whether to fax or copy or print the scanned documents. If you uncheck the Logitech wakeup software from the startup it no longer launches the control center or feeds the document a fraction of an inch. You can manually launch the control center software via Start ->Programs and still be able to scan images
    XLogitech Wirelesslogitechwls.exeAdded by the MYTOB-BS WORM!
    ULogitechCameraAssistantCameraAssistant.exeRelated to Logitech QuickCams and provides additional configuration options for these devices
    ULogitechCameraService(E)ElkCtrl.exeRelated to Logitech Camera Service and provides additional configuration options for these devices
    YLogitechCommunicationsManagercommunications_helper.exeInstalled with a Logitech Quickcam Messenger and if disabled the camera will not work - at least not in the quick capture mode
    NLogitechDesktopMessengerLogitechDesktopMessenger.exeInstalled with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech
    ULogitechGalleryRepairISStart.exeLogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the "U" rather than "Y" recommendation
    NLogitechImageStudioTrayLogiTray.exeLogitech Image Studio - installed with Logitech QuickCams
    NLogitechQuickCamRibbonquickcam10.exeInstalled with a Logitech Quickcam Messenger. Camera's software which is non-essential. When you open it, it allows you to open the quick capture, camera settings, etc
    XLogitechsLogitechs.exeAdded by the SDBOT.BWE WORM!
    NLogitechSoftwareUpdateManifestEngine.exeUpdater, part of Logitech Image Studio - installed with Logitech QuickCam cameras
    ULogitechVideoRepairISStart.exeLogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the "U" rather than "Y" recommendation
    NLogitechVideoTrayLogiTray.exeLogitech Image Studio - installed with Logitech QuickCams
    NLogitechVideo[inspector]InstallHelper.exeLogitech QuickCam software installation helper
    NLogiTrayLogiTray.exeLogitech Image Studio - installed with Logitech QuickCams
    ULogi_MwxLogi_MwX.exeLogitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as "SmartMove". If you disable it and find you don't need it leave it disabled
    ULogMeIn GUILogMeInSystray.exeRemotelyAnywhere is a remote administration and remote control solution for Windows. It allows access to the host computer via the network (the LAN, an intranet or the Internet) - and on the client side all you need is a web browser, a terminal emulator or a WAP-enabled phone
    ULogMeIn GUIragui.exeRemotelyAnywhere is a remote administration and remote control solution for Windows. It allows access to the host computer via the network (the LAN, an intranet or the Internet) - and on the client side all you need is a web browser, a terminal emulator or a WAP-enabled phone
    XLogo[path to trojan]Added by the DLOADER-RH TROJAN!
    ULogon LoaderLogonLoader.exeLogon Loader - customize boot & login screens
    ULogon Loader RandomLogonLoader.exeLogon Loader - customize boot & login screens
    XLogon.exelogon.exeAdded by the ZINS.A TROJAN!
    XLogonAdministratorimoet.exeAdded by the RAHIWI.A WORM!
    ULogonStudiologonstudio.exeWinCustomize LogonStudio - "Allows Windows XP users to edit, change, and apply new logon screens. LogonStudio comes built with a visual editor to make it easy to create your own logons which can then be uploaded to websites to be used by others users"
    XLogServicewincalc.exeAdded by the PAPROXY TROJAN!
    XLogServicelsass.exeAdded by the IU TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
    XLogServicelsrss.exeAdded by the PAPROXY-D TROJAN!
    ULogWatchlogwat95.exeLicensing patch for products installed on NT by Computer Associates such as eTrust. Detects and updates old versions of lic98.dll. Not required if you already have a newer version or the patch has been applied
    Xlololol_hideme_imhiddenlololol.exeAdded by the HIDEME-A TROJAN!
    XlongosWIWT.EXEAdded by the BANKER-CD TROJAN!
    YLook 'n' Stoplooknstop.exeLook 'n' Stop personal firewall
    NLookNMeetAgent.exeLooknMeet dating service
    XLookup_Syslookupsys.exeP04n trojan
    NLotus Organizer EasyClipeasyclip.exe"The Easy Clip icon automates the collection of information from sources such as e-mail to create an Organizer address, appointment, task or Notepad page." Available via Start -> Programs
    NLotus QuickStartsmartctr.exeLotus central application, called SmartCenter, which runs on the Windows desktop. SmartCenter toolbar stretches across the top or, optionally, the bottom of the screen. Uses a lot of resources. Available via Start -> Programs
    ULotus SuiteStartsuitest.exePuts the individual Lotus components in the system tray taskbar when you start Windows. Can be disabled via MSCONFIG -> Startup as "Lotus SuiteStart 97 Edition". All individual components available via Start -> Programs
    XLotusHlpLotusHlp.exeAdded by the WINKO.AO WORM!
    XLowVersionSupport[filename]Added by the LASTRAS TROJAN!
    ULPManagerLPMGR.exePart of Lenovo's IBM ThinkVantage Productivity Center for - "guides you to a host of information and tools to help you set up, understand, maintain, and enhance your ThinkPad? notebook or ThinkCentre? desktop"
    XLprLpr123.exeAdded by the REMPSTEAL password stealer TROJAN!
    XLpr123Lpr123.exeAdded by the REMPSTEAL password stealer TROJAN!
    ULPSLps.exeLocal Port Scanner - "With LPS you're able to check your computer for open or listening ports"
    ULPtasklptask.exeProgram Lock It And Protect Pro - lock and protect your folders from being opened, moved or deleted
    XLRBZ Utility 32lrbz32.exeAdded by the AGOBOT-JQ WORM!
    NLS120 Superdisk??Supposed to accelerate transfer rate on LS-120, contributes to system lockups
    XLSAwfdmgr.exeAdded by the MYTOB.C WORM!
    XLSAlsa.exeAdded by the SDBOT-YV WORM!
    XLSAmsdn.exeAdded by an unidentified malware
    XLSA ServiceLSASS.exeAdded by the AHKER.G WORM! Note - this is not the legitimate lsass.exe process, which should not appear in Msconfig/Startup!
    Xlsa Serviceslsa2srv.exeAdded by the TAME-C WORM!
    XLSA Shell (Export Version)LSASS.exeAdded by several variants of the AHKER WORM! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
    XLSA Shellulsass.exeDetected by Symantec as the SILLYFDC WORM! See here. Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
    XLsaManagerlsamgr.exeAdded by the BEAGLE.DR WORM!
    Xlsaslsas.exeAdded by the BIGFAIRY-C WORM!
    Xlsasslsass.exeAdded by the RATSOU.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a DebugUserMode subfolder of the Winnt or Windows folder
    Xlsassstart.batAdded by the ZCREW TROJAN!
    Xlsass[path to lsass.exe]Added by the ALADINZ.F TROJAN! Note - this is not the legitimate lasss.exe process which should NOT appear in Msconfig/Startup!
    Xlsasslsasrv.exeAdded by the MYDOOM.AG or MYDOOM.AS or MYDOOM.AU WORMS!
    XLsasswoekd.exeAdded by an unidentified WORM or TROJAN!
    Xlsasselite***32.exeEliteBar adware
    XLsassLsass.exeAdded by the ALCOP-B WORM! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
    XLsassLsass.exeAdded by the VOUMIT-A WORM! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "mirc32" folder
    XLsasSSygate.exeAdded by the SDBOT.BCA WORM!
    XLsasskavmm.exeAdded by an unidentified WORM or TROJAN! NOTE - do NOT confuse with the legitimate Kaspersky antivirus module as described here. Contrary to this impostor, the legitimate file will always be located in the Kaspersky Lab folder in Program Files
    XLsassLSASS.EXEAdded by the PUNYA-B WORM! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
    XLSASS 32ISASS32.pifAdded by the ASSIRAL-C WORM!
    XLSASS Authoritylshosts32.exeAdded by the SDBOT-UY TROJAN!
    XLSASS Authoritylsvhosts.exeAdded by the SDBOT.BCE WORM!
    XLSASS DaemonLSASSd.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    Xlsass servicelsass2.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    Xlsass16lsass16.exeAdded by the BANKER-BXX TROJAN!
    Xlsass2k Updatelsass2k.exeAdded by a variant of the RBOT WORM!
    XLSASS32Isass32.exeAdded by the KELVIR.M WORM!
    Xlsass32lsass32.exeAdded by the LYDRA-B TROJAN!
    Xlsass64BiT.exelsass64BiT.exeAdded by the FORBOT-CK WORM!
    Xlsassiglsassig.exeAdded by the BANCOS-EC TROJAN!
    Xlsassslsasss.exeAdded by the GEEKMY-A TROJAN!
    Xlsasss.exelsasss.exeAdded by the SASSER.E WORM!
    Ylsburnwatcherlsburnwatcher.exeHP software which helps one create labels after a music CD is burned using LightScribe discs. If you want to use LightScribe labeling, do not prevent from starting
    YLSBWatcherlsburnwatcher.exeHP software which helps one create labels after a music CD is burned using LightScribe discs. If you want to use LightScribe labeling, do not prevent from starting
    Xlsesslsess.exeAdded by the SINNAKA.A WORM!
    Xlsmasslsmass.exeAdded by the WALLOP-B TROJAN!
    Xlsmss.exelsmss.exeAdded by the PROXY-GG TROJAN!
    ULSPFixLSPmonitor.exeeAcceleration Stop-Sign security software related. Previously not recommended, see here
    Xlspinsigps.exeReported as the VB.KC TROJAN by Kapersky Anti-Virus
    ULSPmonitorLSPmonitor.exeeAcceleration Stop-Sign security software related. Previously not recommended, see here
    Xlssasslssas.exeAdded by the AGOBOT.RL WORM!
    XLSvrLSvr.exePowerStrip foistware. Note - this is not the same as the video tweaking utility of the same name here
    YLT DAEMONltdaemon.exeActs as a data spooler for the DSL modem (similar to a cache). Do not uncheck if the DSL modem is being used
    XLTCISIltcisi.exeAdded by the DELBOT-AP WORM!
    XLTCISIltcisi.exeAdded by the DELBOT-AP WORM!
    XLTDMgrLTDMgr.exePowerStrip foistware. Note - this is not the same as the video tweaking utility of the same name here
    XLTM2MSGSRV32.EXEAdded by the LITMUS.A TROJAN! Note - MSGSRV32.EXE in this case is in a Litmus sub-directory and is not to be confused with the valid version in C:WindowsSystem
    XLTM2MPGSRV32.EXEAdded by the LITMUS.201 TROJAN!
    XLTM2MSGSRV320.EXEAdded by the LITMUS.C TROJAN!
    XLTM2winupdate.exeAdded by the LITMUS.203 TROJAN!
    XLTM2bible.exeAdded by the LITMUS.203 TROJAN!
    XLTM2winscan.exeAdded by the LITMUS-B TROJAN!
    XLTM2lssas.exeAdded by a variant of the LITMUS TROJAN!
    XLTM2MSGSSV32.EXEAdded by the FC.C TROJAN!
    XLTM2msns6Added by the LITMUS.C TROJAN!
    XLTM2RundlI.exeAdded by the MULTIDRP.BG TROJAN!
    XLTM2SVCHOST32.exeAdded by the LITMUS.203B TROJAN!
    XLTM2SVCHOST?.exeAdded by the DROPPERFL.A TROJAN!
    XLTM2winvers16.exeAdded by the SMALL.ND TROJAN!
    ULtMohLtmoh.exeModem On Hold utility - manages incoming/outgoing voice calls on a single phone line while being connected to the internet
    YLTMSGltmsg.exeOne of the "popular" WinModem series. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information
    YLto ManagerDesktopLtoManager.exeRelated to Global Positioning System (GPS) found on HP iPAQ hw6500 unit and others
    NLTSMMSGLTSMMSG.exeLucent Tech. Soft Modem Messaging application - may be found on Fujitsu Lifebook, Acer and Sony Vaio notebooks, maybe others too
    XLTSMSGShell32.exeAdded by the LEMIR.B TROJAN!
    XLTT2rundll32.exeAdded by the LINEAGE-BI TROJAN!
    YLTWinModem1ltmsg.exeOne of the "popular" WinModem series. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information
    Xltwobformatsys.exeAdded by the SERFLOG.A WORM!
    Xltwobmsmbw.exeAdded by the SERFLOG.A WORM!
    Xltwobserbw.exeAdded by the SERFLOG.A WORM!
    ULUGuardLUGuard.exePC-Duo Remote Control enables your help desk technicians to take instant control of any remote desktop PC at any location across the LAN, WAN or internet
    Xluplup.exeAdded by the IRCBOT_GEN WORM!
    YLusetupLUSetup.exeSymantec LiveUpdate installer - required to install a new version of the application. Will only run once, and the entry is automatically deleted after a reboot
    ULVComslvcoms.exeLvcomm server. Related to Logitech Quick Cam - works fine without it but it is needed for the Logitech ImageStudio software to connect to the camera
    NLVCOMSXLVCOMSX.EXEIt provides extra functionality for Logitech multimedia webcam devices. When disabled the camera still works in quick capture but you can get a slight increase in picture quality - not so snowy and the movement wasn't so jerky
    ULWBKEYBOARDKbdAp32A.exeKeyboard utility for a Labtec brand (and possibly others) keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard
    ULWBMOUSElwbwheel.exeMouse driver - required if you use non-standard Windows driver features
    ULWBMOUSEMOUSE32A.EXEMouse utility for a Lenovo brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
    NLwinst Run Profilerlwtest.exeLogitech Wingman Profiler for the Logitech joysticks. Available via Start -> Programs
    Xlwjcjuti.exelwjcjuti.exeAdded by the DWNLDR-GTQ TROJAN!
    Ylxamsp32lxamsp32.exeLexmark Scan and Copy Control Program for the X63 (and maybe others) printer/scanner. Required for the scanner to work
    ?LXbbmgrLXbbmgr.exeLexmark printer button manager? Is it required?
    ?LXBLKskLXBLKsk.exeLexmark related. What does it do, and is it required?
    Ulxbrbmgrlxbrbmgr.exe"Lexmark Scan & Copy Control Program" for the Lexmark 3100 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc
    ?LXBRKskLXBRKsk.exeLexmark printer related. What does it do and is it required?
    YLXBSCATSrundll32 [path] LXBStime.dll, _RunDLLEntry@16Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    YLXBTCATSrundll32 [path] LXBTtime.dll, _RunDLLEntry@16Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    YLXBUCATSrundll32 [path] LXBUtime.dll, _RunDLLEntry@16Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    Ulxbumon.exelxbumon.exeLexmark 6200 Series printer device monitor
    YLXBXCATSrundll32 [path] LXBXtime.dll, _RunDLLEntry@16Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    Ulxbxmon.exelxbxmon.exeLexmark 7100 Series printer device monitor
    YLXBYCATSrundll32 [path] LXBYtime.dll, _RunDLLEntry@16Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    Ulxbymon.exelxbymon.exeLexmark P910 Series printer device monitor
    YLXCCCATSrundll32 [path] LXCCtime.dll, _RunDLLEntry@16Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    Ulxccmon.exelxccmon.exeLexmark 3300 Series printer device monitor
    YLXCECATSrundll32 [path] LXCEtime.dll, _RunDLLEntry@16Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    YLXCFCATSrundll32 [path] LXCFtime.dll, _RunDLLEntry@16Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    YLXCGCATSrundll32 [path] LXCGtime.dll, _RunDLLEntry@16Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    Ulxcgmon.exelxcgmon.exeLexmark 2300 Series printer device monitor
    YLXCJCATSrundll32 [path] LXCJtime.dll, _RunDLLEntry@16Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    YLXCQCATSrundll32 [path] LXCQtime.dll, _RunDLLEntry@16Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    Ulxcqmon.exelxcqmon.exeLexmark 9300 Series printer device monitor
    YLXCRCATSrundll32 [path] LXCRtime.dll, _RunDLLEntry@16Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    Ulxcrmon.exelxcrmon.exeLexmark 2400 Series printer device monitor
    YLXCTCATSrundll32 [path] LXCTtime.dll, _RunDLLEntry@16Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    Ulxctmon.exelxctmon.exeLexmark 5400 Series printer device monitor
    YLXCYCATSrundll32 [path] LXCYtime.dll, _RunDLLEntry@16Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    Ulxcymon.exelxcymon.exeLexmark 3400 Series printer device monitor
    Ulxdcamonlxdcamon.exeLexmark 1300 Series printer device monitor
    YLXDCCATSrundll32 [path] LXDCtime.dll, _RunDLLEntry@16Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details
    Ulxdcmon.exelxdcmon.exeLexmark 1300 Series printer device monitor
    Ulxddamonlxddamon.exeLexmark 2500 Series printer device monitor
    Ulxddmon.exelxddmon.exeLexmark 2500 Series printer device monitor
    Ulxdiamonlxdiamon.exeLexmark 3500-4500 Series printer device monitor
    YLXDICATSrundll32 [path] LXDItime.dll, _RunDLLEntry@16Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll)
    Ulxdimon.exelxdimon.exeLexmark 3500-4500 Series printer device monitor
    Ulxdjamonlxdjamon.exeLexmark 1400 Series printer device monitor
    Ulxdjmon.exelxdjmon.exeLexmark 1400 Series printer device monitor
    NLXSUPMONLXSUPMON.EXELexmark printer related. The printer should work fine without it but what does it do?
    ?lycosInsideLyc_SysTray.exeLycos eMail related - what does it do and is it required?
    ULyraHD2TrayAppLYRAHD2TrayApp.exeRelated to RCA Lyra MP3 Player
    XLzioMediaUpdaterLzioMediaUpdater.exeLZIO.com adware downloader
    ?M Player Post Installerpostinstallm.exe??
    XM S DVD DirectX Dll Driversmsxdl.exeAdded by the SDBOT-BJN WORM!
    NM-Audio Delta Taskbar IconDeltTray.exeM-Audio Delta Control Panel for M-Audio brand Delta series audio cards. System Tray access to audio settings - available through Control Panel
    UM-Audio MobilePre Control Panel LauncherMPTask.exeControl Panel Launcher for MobilePre USB bus-powered preamp and audio interface from M-Audio
    XM-soft OfficeM-soft Office.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
    XM1cr0s0ft S3rcuritysystemconfig.exeAdded by the RBOT.BKB WORM!
    XM1cr0s0ft Upd4t4zSupdate32.exeAdded by the RBOT-MI WORM!
    Xm32infom32info.exeAdded by the CRYPTER.A TROJAN!
    XM3Development_WhenUSave_InstallerM3Development_WhenUSave_Installer.exeWhenU.Save adware
    NM3Traym3tray.exeMovielink - internet movie rental System Tray access
    UMAAgentMAAgent.exeRelated to MarkAny - a solution to prevent is unauthorized distribution of information through Floppy, CD, email, etc
    XMacfee Security PatchMpfsheild.exeAdded by the RBOT-NP WORM!
    UMachine Debug Managermdm.exeUsed by developers for debugging. Those who have encountered it have unchecked it with no degradation in performance. May cause your computer to "hang" if you have MS Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendatioon. Can also be listed as MDM7. See here to disable
    XMachine Debug Managermsdn.exeAdded by a variant of the RBOT WORM!
    XMachine Update Softwusas.exeAdded by an unidfentified WORM!
    Xmachine-debuggerWMIPRVSW.exeAdded by the AGOBOT.U WORM!
    Xmackfy.exemsms.exeAdded by the SDBOT-DID WORM!
    NMacLicMacLic.exePart of Conversions Plus from DataViz - allowing PC and MAC owners to share disks
    NMacLicenseMacLic.exePart of Conversions Plus from DataViz - allowing PC and MAC owners to share disks
    NMacNameMacName.exePart of Conversions Plus from DataViz - allowing PC and MAC owners to share disks
    XMacromedia 8Flash Player.exeAdded by the JAMBU-A WORM!
    XMacromedia Critical Updaterrarww.exeAdded by a variant of the RBOT WORM!
    XMacromedia Dreamweaver XMmacdwXM.exeAdded by the AGOBOT-RI WORM!
    XMacromedia DriveIexplor32.exeAdded by a variant of the RBOT WORM!
    XMacromedia Flash Updatescvhost.exeAdded by a variant of the RBOT WORM!
    YMAD.EXEMAD.EXEMAD.exe is the MS Exchange 5.5 System Attendant and can also consume a large amount of resources - resolved by the latest Exchange 5.5 Service Pack. Also part of Exchange 2000 Server but does it have the same problems?. Apparently you need to leave this running but is it needed at start-up?
    NMadExeLaunchRA.exePart of Dell Resolution Assistant - "a diagnostic program that allows you to contact Dell. When factory-installed by Dell, it allowed you to perform hardware and software diagnostics that provided alerts to potential problems and enabled real-time communication with Dell RA techs. You can now use RA only to contact Dell by e-mail"
    UMAFWTaskbarAppMAFWTray.exeDrivers for the M-Audio Firewire Audiophile - Interface
    UMagicDskMAGICDSK.EXEMagic DeskTop is a small and novel utility which will allow you the option of hiding or showing your desktop icons
    UMagicKeyboardPreMKBD.exeRelated to Samsung laptops. Provides ability to program keys to perform specific functions
    UMagicLinker3MagicLnk.exeThaiSoftware Thai Dictionary
    NMagitimeMagitime.exeMagitime - connection tracking utility which monitors online time, expense, data transfer
    ?Mail.commcalert.exeMail.com - free web-mail service. Does mcalert.exe notify you when new mail has arrived?
    UMailBellmailbell.exeMailBell e-mail notification tool that will notify you about new messages arrived to your mailbox. Works with both POP3 mailboxes and web-mail based systems. You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance)
    UMailbox Verifiermboxvrfy.exeMailbox Verifier (MV) is free software that will notify you about new messages arrived to your mailbox. Only works with POP3 mailboxes (not web-mail based systems). You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance)
    UMailCleanerMAILCLEANER.EXEMailCleaner "protect your computer from viruses sent to your machine via the popular e-Mail reader Incredimail. In addition the program will check all incoming files downloaded by Internet Explorer, Netscape Navigator, ICQ and iMesh". Not recommended as it bundles GAIN adware. Please note that Claria Corporation no longer support GAIN-Supported software - see here
    Xmailman.exemailman.exeAdded by the CERTIF-E TROJAN!
    YMailScan DispatcherLaunch.exeMicroWorld MailScan Dispatcher splits each e-mail message into various components such as the header, body and attachment. Compressed formats (ZIP, ARJ, etc.) are scanned for viruses and cleaned
    XMail_CheckMail_Check.exeAdded by the PANOIL.C WORM!
    UMAINmain.exeSpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan
    ?Main Executable (HP)HP05T0R5.exeHP (Hewlett-Packard) related. Maybe related to printers. Now - what does it do?
    Xmain16main16.exeAdded by the CRYPTER.A TROJAN!
    Xmain32main32.exeAdded by the CRYPTER.A TROJAN!
    XMainStartsvcmfte32.exeAdded by the STINX-A TROJAN!
    Xmainviewexmainviewex.exeAdded by the GEMA.D TROJAN!
    Xmain_moduledrvmmx32.exeAdded by the DILA TROJAN!
    XMajor Microsoft Windows Driver Boot loaderbpool.exeAdded by the MYTOB.AJ WORM!
    UMalware SweeperMalSwep.exeMalware Sweeper - "Protects the user from malicious malware and monitors the sanity of the running programs"
    XMalware-WipeMalware-Wipe.exeMalware remover - not recommended, see here
    XMalware-WipedMalware-Wiped.exeMalware remover - not recommended, see here
    XMalwareAlarmMalwareAlarm.exeMalwareAlarm malware remover - not recommended, see here
    XMalwareBotMalwareBot.exeMalwareBot spyware remover - not recommended, see here
    XMalwareCrushMalwareCrush.exeMalwareCrush spyware remover - not recommended, see here
    XMalwareStopperMalwareStopper.exeMalwareStopper malware remover - not recommended, see here
    XMalwareWipeMalwareWipe.exeMalwareWipe malware remover - not recommended, see here
    XMalwareWipedMalwareWiped.exeMalwareWiped malware remover - not recommended, see here
    XMalwareWiperMalwareWiper.exeMalwareWiper malware remover - not recommended, see here
    UManageDesk LiteManageDesk Lite.exeManageDesk Lite from Managebytes Desktop management software. Each desktop is a separate working space for you to use
    XManageProtocolCtrlcsmsv.exeAdded by the LOOKSKY.B TROJAN!
    Xmanagermanager.exeDetected by Kaspersky as the SMALL.CVT TROJAN!
    UManager Monitormonitor.exeMindStorm AnalyzerPro from Secure Associates. "A security management tool for customers easy to manage report and analyze security events across heterogeneous security devices"
    XManagment Service[random filename]Added by the RBOT.BIS TROJAN!
    NMania Win RestoreRESWIN.EXEPinball Mania for Windows from 21st Century Entertainment LTD (1995). Runs briefly at start-up then terminates. Available via Start -> Programs
    Xmanrotcemanrotce.exeAdded by unidentified malware
    XMantis[filename]Added by the MANTIBE VIRUS!
    XMapEDCMapEDC.exeAdded by the WaveRevenue-McBoo TROJAN!
    XMapiDrvmpisvc.exeAdded by the MIPSIV TROJAN!
    Xmapisvc32mapisvc32.exeAdded by the KX VIRUS and also recognised by Symantec as FPAI adware
    Xmark the servicexxtra32.exeAdded by the SDBOT.APP WORM!
    XMartinipinmart.exeAdded by a variant of the SDBOT WORM!
    XMascro soft SDK updates2SDKrepair2.exeAdded by the SDBOT.BXM WORM!
    Xmaskridermaskrider2001.vbsAdded by the SOLOW-G WORM!
    Nmasqform.exemasqform.exePureEdge Viewer 6.0, reportedly associated with viewing and text editing US Air Force electronic forms
    Umasqform.exemasqform.exePureEdge Viewer - provides automation framework to manage and deploy XML forms-based processes for e-business and e-government systems. PureEdge was taken over by IBM (see here) and the product became Workplace Forms
    NMass storage check registryrundll32.exe MSDServ.dll, check registryUsed with a USB based smartmedia card reader
    XMastersvcghost.exeAdded by the IRCBOT.RB TROJAN!
    XMaster Card Updaate 32Mastercard32.exeAdded by a variant of the RBOT WORM!
    UMaster Volume SpyMASTERVOLUMESPY.EXEVolume control for the Gateway Destination "DestiVu" media interface
    XMasterBoot Switchpopupkill.exeAdded by a variant of the RBOT WORM!
    UMatadormlfbuddy.exeMailFrontier - anti-spam application
    UMatadormantispm.exeMailFrontier Desktop (Matador) email spam blocker software
    UMatrix Screen Lockermatrix.exeMatrix Screen Locker is a system tray application that allows for quick and secure PC lock when you wish. The screen does a "matrix style" scrolling characters effect when the lock is running
    XMatrixScreen[filename]Added by the MATRIXSCREEN TROJAN!
    XMatrixScreenSavermss.exeMalware, see here
    NMatrox Color Controlhgcctl95.exeFor Matrox video cards. Quick access to changing colors
    NMatrox Control Centermgactrl.exeFor Matrox video cards. Quick access to settings
    NMatrox Diagnosticmgadiag.exeFor Matrox video cards. Quick access to diagnostics
    NMatrox PowerdeskPDesk.exeFor Matrox video cards. Quick access to tweak your card to your liking
    NMatrox PowerDesk 8Matrox.PowerDesk.exe /silentFor Matrox video cards. Quick access to tweak your card to your liking
    NMatrox PowerDesk 8matrox.powerdesk.exe"Matrox PowerDesk software provides extra multi-display desktop management controls"
    NMatrox QuickDeskmgaqdesk.exeFor Matrox video cards. Quick access to tweak your card to your liking
    XMAV_checkmav_startupmon.exeWinAntiVirus Pro 2007 misleading virus software - not recommended, see here
    XMaxAlertsmax.exeBonzi MaxALERT - spyware
    UMaxBackSchedulemaxbackservice.exeBackup scheduler for the Maxtor (now Seagate) range of external hard drives - part of Maxtor Quick Start
    UMaxBlastMonitorMaxBlastMonitor.exeMaxblast hard drive utility for Maxtor (Seagate) drives
    YMaxtorComboComboButton.exeRequired to be able to use the Maxtor OneTouch button on your external Maxtor harddrive. It is used to start up backup software (Retrospect)
    UMaxtorOneTouchOneTouch.exeMaxtor OneTouch Hard Drives/OneTouch Family hard disk backup software
    UMaxtorRegAUTOREG.EXEPart of SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of
    YMayaPanMayaPan.ExeAudiotrak Maya soundcard driver
    Xmb2np[random filename]Added by the IRCBOT.TJ WORM!
    UMBkLogOnHookLogOnHook.exeRelated to McAfee Backup from Network Associates
    UMBM 4MBM4.exeMotherboard Monitor 4 - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs
    UMBM 5MBM5.exeMotherboard Monitor 5 - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs
    ?MBMonRundll32 CTMBHA.DLL, MBMonCreative Filter AudioControlMB Module - related to the Creative Audigy line of sound cards. What does it do and is it required?
    UMBNetmbnet.exeMBNet (Portugal) Credit Card Processing software
    UMBProbembrpobe.exeMBProbe - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs
    Umbssm32mbssm32.exeReported as Micro Bill Systems foistware - but not according to the company themselves, see here
    Xmbssm32monstu.exeDetected by AVG Antispyware as the AGENT.CNM TROJAN!
    XMCwintrims.exeAdded by the WINTRIM TROJAN!
    XMCMAGICON.EXEAdded by the MAGICON.A TROJAN!
    XMCN/AAdded by the SIMCSS TROJAN!
    XMCWINTRIM.EXEAdded by the WINTRIM_A TROJAN!
    XMcAfeeMcAffeAv.exeAdded by the NETSKY.AL WORM!
    XmcafeeWin32.dll.vbsAdded by the CATCHER-B WORM!
    XMcafee Anti ScanNortonScn.exeAdded by a variant of the RBOT WORM!
    XMcAfee AntivirusMcAfeeAV.exeAdded by a variant of the RBOT WORM!
    XMcafee Antivirus Monitoring System326VSStatmn326.exeAdded by a variant of the SDBOT WORM!
    XMcafee Antivirus Monitoring System32mnVSStatmn32.exeAdded by a variant of the RBOT WORM!
    XMcAfee Antivirus ProtectionmcafeeAV.exeAdded by a variant of the RBOT WORM!
    XMcafee Auto Protectmcafeshield.exeAdded by the RBOT-UH WORM!
    UMcAfee BackupMcAfeeDataBackup.exeMcAfee Backup from Networks Associates
    YMcAfee Desktop Firewall TrayFireTray.exeMcAfee Desktop Firewall
    YMcAfee FirewallCPD.EXEFirewall bundled with McAfee VirusScan 6.*. Can also be listed as CPD_EXE
    NMcAfee GuardianCMGRDIAN.EXEMcAfee's QuickClean, an offline version of the one in their online Clinic. Normally run offline and not needed. Incidentally, incorporates more cleanup programs than the likes of WinOptimizer and System Mechanic
    XMcAfee Online virus Scanneravp.exeAdded by the RBOT-GCV WORM! Not to be confused with AOL's Active Virus Shield (by Kaspersky)
    XMcAfee Online Virus Scannernzm.exeDetected by Trend Micro as the IRCBOT.XV TROJAN! See here
    NMcAfee QuickClean ImonitorPlguni.exeMcAfee QuickClean 3.0 - removes internet clutter and unwanted programs
    Xmcafee Software Intrenetmcafee.exeAdded by the RBOT-ATR WORM! Note - this is not a valid McAfee program
    XMcAfee Windows Protectionmcafee32.exeAdded by a variant of the SPYBOT WORM!
    NMcAfee Winguage??Part of McAfee Nuts & Bolts. "WinGuage is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious". Resource hog. Available via Start -> Programs
    UMcAfee.InstantUpdate.MonitorRuLaunch.exeInstant Updater for McAfee's VirusScan, Internet Security, Quick Clean, Uninstaller and Firewall products. In the case of VirusScan leave it enabled unless you update manually on a regular basis
    YMcAfeeFireTrayFiretray.exeMcAfee Desktop Firewall
    XMcAfeeScanPlusMcAfeeScanPlus.exeAdded by the MEPCOD TROJAN! This trojan file does not belong to any McAfee Antivirus Software and is found in the Windows or Winnt folder
    YMcAfeeUpdaterUIUpdaterUI.exeAssociated with McAfee Enterprise 7.0.0. - background process
    YMcAfeeVirusScanServiceAvsynmgr.exeFrom McAfee VirusScan version 5.x. Runs VirusScan System Tray (Vsstat.exe), WebScanX (Webscanx.exe), VirusScan System Scan (Vshwin32.exe) and VirusScan Console (Avconsol.exe) under one application
    YMcAfeeWebscanXWebScanX.exeFrom McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc
    XMcaffe AntivirusMcafeescn.exeAdded by a variant of the SPYBOT WORM!
    XMcaffeemcsheild.exeAdded by the RBOT-FDP WORM!
    UMcAgentExemcagent.exeFrom McAfee VirusScan On-line. The Agent is a red M icon that appears in the Windows system tray or Notification Area (if you're running Windows XP). If you don't see the agent icon, VirusScan Online may not be installed
    YMcappins.exemcappins.exeUsed by McAfee Virusscan to perform product updates. When updates are available the program will download and install them automatically. Recommended to leave enabled
    NMChangerMChanger.exeMedia Changer - utility that allows you to change wallpapers, sounds, themes, etc
    UMCI USB IconUSBIcon.exeMCI USB software used for managing a USB card reader
    NMcLogLch_exeMcLogLch.exeRelated to McAfee security suite. This is a non-essential program, but should not be disabled unless suspected to be causing problems
    XMCM3mcm3.exeShopAtHome/SAHagent adware variant
    ?McRegWizmcregwiz.exeMcAfee antivirus related. What does it do and is it required?
    XMcrosoftr UpdateMcrosoftr.exeAdded by a variant of the RBOT WORM!
    YMcShld9xmcshld9x.exePart of McAfee's Virusscan Online. Must be enabled for scanning to work
    YMCTskShdmctskshd.exePart of McAfee SecurityCenter. Runs in the background controlling critcal updates and control antivirus related actions. This program is important for the stable and secure running of your computer
    UMcUpdateExemcupdate.exeFrom McAfee VirusScan On-line. Automatically updates your virus definitions. Leave enabled unless you regularly update these definitions
    YMcVsRtemcvsrte.exePart of McAfee's SecurityCenter. Must remain checked but one user reports Windows glitches with no response from McAfee as to why
    Ymcvsshldmcvsshld.exeMcAfee VirusScan On-line. See also the McAgentExe entry
    XMCX Updatewisp.exeAdded by the RBOT-AQH WORM!
    XMCX Updtescorti.exeAdded by the RBOT-ARP WORM!
    XMD IE Pluginmd.exeMarketdart spyware
    XMD IE Pluginwiny.exeAdware
    Nmdac_runoncerunonce.exeAssociated with MS Data Access Components (MDAC). Sometimes left over after installation - not required. NOTE :- don't delete "runonce.exe". 
    NMDDiskProtect.exeMDDiskProtect.exeMediaFour MacDrive for Windows - easily open, edit and save files from Mac-formatted disks, format Mac disks and burn Mac CDs and DVDs!
    Xmdetect[path to trojan]Added by the SPABOT TROJAN!
    XMdmMdm.vbsAdded by the WHITEHO VIRUS or TRAPPY WORM!
    Xmdmmdm.exeAdded by the LYDRA-F TROJAN! Note - this is not the valid Machine Debug Manager which shares the same filename
    UMDM7mdm.exeUsed by developers for debugging. Those who have encountered it have unchecked it with no degradation in performance. May cause your computer to "hang" if you have MS Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendatioon. Can also be listed as Machine Debug Manager. See here to disable
    XMdmdllmdmdll.exeAdded by the CRYPTER TROJAN!
    XMdmdll32mdmdll32.exeAdded by a variant of the CRYPTER.C TROJAN!
    XMDNMDNS.exeAdded by the SPYBOT.JPB WORM!
    XMDNMDNZ.exeAdded by the RBOT.AQD WORM!
    XMDNMDN.exeAdded by the RBOT.AOA WORM!
    XMDNSservice.exeDetected by Symantec as a variant of the Mirar adware
    Xmds.exemds.exeAdded by the MADS-A TROJAN!
    XMDSA Sentinel Xsmss.exeSentinelX spyware. Note - SentinelX is spyware that logs keystrokes. It also monitors and records Web sites visited and applications used. The risk can capture periodic screen shots and may be configured so as to block access to specific Web sites and chat rooms, must be manually installed. Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "MDSA Software" subfolder of the Program Files folder
    Xmdwmdmspmdwmdmsp.exeAdware - detected by Kaspersky as the AGENT.AM TROJAN!
    NMECAMeca.exeMeca cross-platform communications technology, branded messengers will connect with AOL, MSN, Yahoo!, and ICQ users
    XMedGSMEDGS1.exePacerD_Media/Pacimedia.com adware
    XMedia AccessMediaAccK.exeWindupdates MEDIAPAS.A adware
    XMedia AccessMediaAccK.exeAdded by the PODROP-C TROJAN!
    XMedia Adapterbitblt.exeAdded by the HANSAH-A WORM!
    UMedia Card Companion MonitorMCC Monitor.exeMonitor for Media Card Companion from ArcSoft. "Automates the tedious processes associated with downloading and sharing files from digital cameras, card readers, and other removable media"
    UMedia Codec Update Serviceupdate.exeWindows Essentials Codec Pack 1.0 is a collection of the most commonly needed video and audio codecs. This program allows keeps these codecs updated
    XMedia GatewayMediaGateway.exe180Solutions adware related
    XMedia Loadmsn32.exeAdded by a unidentified WORM or TROJAN!
    UMedia Manager IndexerAIRSVCU.EXEPart of MS Visual InterDev, Media Manager is an easy media file management system that works in conjunction with Windows Explorer. The Media Manager Indexer is a program that indexes all the information about your media files and puts it into a database
    XMedia PassMediaPassK.exeMediaPass adware
    XMedia PassMediaPass.exeWindUpdates MediaPass adware
    XMedia Playermedia.exeAdded by the FLDMEDIA-A TROJAN!
    XMedia Playerwmplayer.exeAdded by the AGOBOT-BM WORM!
    XMedia PlayerSysdll.exeAdded by the BANKER-BR TROJAN!
    XMedia PlayerSysnet.exeAdded by the BANKER.MW WORM!
    XMedia Player Updatexpsp1mfh.exeAdded by a variant of the RBOT WORM!
    XMedia Plug x.1.2msdm.exeAdded by the MULDROP.352 VIRUS!
    XMedia Servermsdts.exeAdded by a variant of the IRCBOT TROJAN!
    XMedia Servicemsn64.exeAdded by the SPYBOT.EV WORM!
    XMedia servicemsnmsgxr.exeAdded by the SDBOT.TF WORM!
    XMedia serviceSYSTEM64.EXEAdded by the RBOT.QV WORM!
    XMedia servicenotpad.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    XMedia Software UPdatersscs.exeAdded by the RBOT-ABE WORM!
    XMedia Transfer Protocalsmsstc.exeAdded by a variant of the IRCBOT TROJAN!
    XMedia X ServicesMSNGRx.exeAdded by the RBOT.AUL WORM!
    XMedia-XP-Service-Pack3msnzx.exeAdded by the SDBOT-ACW WORM!
    XMEDIA32[path to trojan]Added by the PURSCAN-Z TROJAN!
    NMediaFace IntegrationSethook.exeFellowes Neato? cd label design software. "Launch NEATO's MediaFACE II label making software directly from the productname toolbar"
    UMediafour Mac Volume NotificationsMacvntfy.exeMediafour Xplay - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod
    UMediafour XPlay Tray Notification IconXptryicn.exeMediafour Xplay - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod
    UMediaKeyMediaKey.exeMultimedia keyboard manager. Required if you use the multimedia keys
    UMediaLifeServiceMediaLifeService.exeRelated to MediaPlay Cordless Mouse from Logitech
    XMediaLoadsdw.exeMedialoads adware
    XMediaLoads Installerdw.exeMedialoads adware
    NMediaMonitorMediam~1.exeInstalled by Smartdisk MVP CD burning software. Software will work fine without it
    Xmediamotor.exemmups.exeAdded by the AGENT-BY TROJAN!
    XMediaPathProyecto1.exeAdded by the GRUEL WORM!
    XMediaPathRoot.exeAdded by the GRUEL WORM!
    XMediaPipe P2P Loadermpp2pl.exeMediaPipe peer-to-peer file swapping program also reported as a hijacker
    Xmediapluscash.exemediapluscash.exeMediaGateway adware
    NMediaRing Talkmrtalk.exeMedia Ring Talk, voice recognition software, Resource hog. Available via Start -> Programs
    XMediaXPServicePackmxpsp.exeAdded by the SDBOT.CDT WORM!
    Xmedia_drivermedia_driver.exeAdded by the TUPEG VIRUS! Note - this malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot. Name field may be empty
    Xmedia_managermediaman.exeMini-Player,  IMESH related foistware, see here
    Xmedia_stubstub.exeMini-Player,  IMESH related foistware, see here
    UMEDICsprtcmd.exe /P MEDICSelf-help support tool for an unidentified high-speed internet provider (provided by SupportSoft, Inc). Identifies and automatically fixes typical problems that may occur with your high-speed internet service
    XMedichimedichi.exeAdded by the VIRANTIX.B TROJAN!
    XMedichi2medichi2.exeAdded by the VIRANTIX.B TROJAN!
    ?MedionVFDMdionLCM.exeRelated to Medion Display Information. What does it do and is it required?
    XMeeting Connectioncomsutil.exeAdded by the PPDOOR-E TROJAN!
    XMeeting Connectionwowdache.exeAdded by the PPDOOR-D TROJAN!
    XMeeting Connectionhgakdl32.exeLooks like a variant of the PPDOOR-E TROJAN!
    UMegaPanelHSTrans.exeHomescan Internet Transporter - part of ACNielson Homescan. Recognizes when the ACNielsen Homescan Scanner is attached to the computer and allows it to transmit scanner information to ACNielsen
    ?meidntpavqgdpfrs.exe??
    Xmelg34mdmd.exeAdded by an unidentified WORM or TROJAN - see here
    Xmelg3445mdmdd.exeAdded by a variant of the RBOT WORM!
    Xmem32mem32.exeAdded by the AGENT-FWF WORM!
    XMembers area******.exe [* = random digit]Premium rate adult content dialer
    XMemConfigSetupIE.comAdded by the TAPLAK WORM!
    NMementoMemento.exeMemento - simple app to keep text notes on your desktop
    UMemMonstermemmnstr.exeMemMonster - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
    UMemoKitMK.EXEMemory optimizer. It loads from startup group and it goes off as soon as the program (memokit.exe) is loaded in the System Tray. Mk.exe does not run while the memokit.exe is running. Probably loads a flash screen at startup and shutdown that stays on screen less than 5 seconds and gives you a button to push to purchase the full version. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
    Xmemoryoutlookrem.exeAdded by the NOPIR.C WORM!
    XMemory Allocation Hostcihost.exeDetected by Avast as a variant of the IRCBOT-CHZ WORM!
    XMemory Allocation Serverciserv.exeAdded by an unidentified malware
    XMemory Allocation Servicescisrv.exeDetected by Trend Micro as the IRCBOT.FC TROJAN! See here
    XMemory Checkmemore.exeAdded by the KILLAV.C TROJAN!
    XMemory managerhimem32.exeAdded by the MANCSYN TROJAN!
    XMemory Managermemorymanager.pifAdded by the DELF-JJ TROJAN!
    XMemory relocation servicereloc32.exeAdded by the RELFEERWORM!
    XMemory Servicefreememory.exeAdded by the RBOT.GEN WORM!
    NMemory Stick MonitorMSTAT.exeUsed with the Sony floppy disk adapter for memory sticks, showing if there is a stick in the computer
    UMemory Stick MonitorMSstat.exeSony/SmartDisk memorystick-floppydisk-adapter software - allows you to read memorysticks in a normal floppydrive
    XMemory WatcherMemoryWatcher.exeMemoryWatcher spyware
    UMemory+tfimemsr.exeMemory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
    UMemoryBoostMemoryBoost.exeMemoryBoost - memory optimizing program made by Tenebril Inc. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/ME. See this article and make up your own mind
    UMemoryCardManagerMemCard.exeMemory Card Manager - for removable memory cards found on Dell or Lexmark photo printers
    XMemoryManager[random name].dllVirtumondo adware related
    XMemoryMeterMemoryMeter.exeAutoinstalling spyware by Total Velocity
    UMemoryZipperPlusmemzip.exeMemory Zipper Plus - "optimizes the memory management of your system and boost-up its performance amazingly!"
    Xmemreader.exememreader.exeAdded by the AGOBOT-TY WORM!
    XMEMrealoadMEMreaload.exeAdded by the LAZAR TROJAN!
    XMemScannerMemScanner.exePart of Enigma SpyHunter - not recommended, see note
    UMemTurbomemturbo.exeMemTurbo memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
    NMenuSnapMenuSnap.exeMenuSnap from Rietta Solutions. Utility that re-orders your Start Menu items alphabetically. You may not want this utility if you're able to do this manually by selecting Start -> Programs and right-clicking and choosing "Sort by Name" if availabe
    NMercoraMercoraClient.exeMercora MusicSearch "Search, find and listen to music on the world's largest jukebox, built by people just like you". Note - if you subscribe make sure you read the Privacy Policy
    XMessage Queuingmsmqs.exeAdded by the FREEFORS TROJAN!
    NMessagerStarter FreeserveStartMessager.exeFreeserve Messenger
    UMessage_Blockermessageblock.exeMessage Blocker - "prevents Outlook Express from loading images or other content from the internet without confirmation, as well as executing scripts when displaying a formatted email message"
    XMessangertrillian.exeAdded by the RBOT.CKI WORM!
    XMessangerdeamon.exeAdded by the TACTSLAY.C TROJAN!
    XMessangermsgaol.exeAdded by the TACTSLAY.C TROJAN!
    YMessangers_menu.exeAdded by the TACTSLAY.C TROJAN!
    XMessangerbrowse.exeAdded by the TACTSLAY.C TROJAN!
    XMessengermessenger.exeAdded by the KUTEX TROJAN!
    XMessengerntsubsys.exeAdded by the SDBOT.BGE WORM!
    XMessengerWmsngr.exeAdded by a variant of the RBOT WORM!
    YMessengerSCANMSG.EXEAntiVirus Quick Heal - virus protection
    XMessenger Blockmsngrblock.exeAdded by the PATOO WORM!
    XMessenger Journelusnsvc.exeDetected by Trend Micro as the RBOT.FKT WORM! See here
    XMessenger Protocolnetsender.exeAdded by the SDBOT-ACC WORM!
    XMessenger Servicemsmsgs.exeAdded by the SDBOT-ZB WORM!
    XMessenger Servicenvhost.exeAdded by the JLOK-A WORM!
    XMessenger Service Updatersvshost.exeAdded by the MYTOB.GC WORM!
    XMessenger Sharing Controlmnwsvc.exeAdded by a variant of the IRCBOT TROJAN! See here
    XMessenger start-upMsgran.exeAdded by the GRAMOS WORM!
    XMessenger6command.pifAdded by the INZAE.B WORM!
    UMessengerDiscoveryMessengerDiscovery.exeMessengerDiscovery is a MSN Messenger add-on - adding over 70 new features. Now superseeded by MessengerDiscovery Live - with support added for Windows Live
    NMessengerPlusMsgPlus.exeMessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"!
    NMessengerPlus2MsgPlus.exeMessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"!
    NMessengerPlus3MsgPlus.exeMessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"!
    XmessengerskinnerMessengerSkinner.exeMessenger Skinner malware - uses a rootkit to hide executable files
    Xmessnger[worm filename]Added by the DELODER WORM!
    XmessngerDvldr32.exeAdded by the DELODER.A WORM!
    NMetacafeMetacafeAgent.exeMetacafe - video sharing on the web. Note - if you subscribe make sure you read the Privacy Policy
    XMeTaLRoCk (irc.musirc.com) has sex with printersmetalrock-is-gay.exeAdded by the RANDEX.Q WORM!
    XMeuProgramaaccwizz.exeAdded by the RULAND.A WORM!
    XMfc**.exe [* = random char]Mfc**.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
    XMfc**32.exe [* = random char]Mfc**32.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
    ?mfgboot????
    XmFilterMNeck.exeAdded by the CLICKER-AG TROJAN!
    Xmfin32mfin32.exeMyFreeInternetUpdate - adware downloader
    YMFP Server AgentMFPAgent.exeMulti Function Printer (MFP) Server Agent for Belkin's Wirless G All-in-One Print Server and ZyXEL's NPS-520
    ?MGA HookMgahook.exeMATROX Graphics card related. What does it do and is it required?
    NMGA QuickdeskMGAQDESK.EXEFor Matrox video cards. Quick access to tweak your card to your liking
    UMgabgMgabg.exeMatrox BIOS Guard - monitors a Matrox card's BIOS, and will reflash it when needed. Cards like the G400 have a nasty habit of losing their BIOS, especially on poor power supplies. If you make an emergency BIOS disk with the utility in their BIOS package, you can disable Mgabg.exe and just use the crash disk if/when needed
    Ymgavctrlmgavrtcl.exeMcAfee's Virus Scan Online
    Ymgavctrlmgavrte.exeMcAfee's Virus Scan Online
    Ymgavrtclexemgavrtcl.exeMcAfee's Virus Scan Online
    Ymgavrtclexemgavrte.exeMcAfee's Virus Scan Online
    NMGA_CD_Installmgasetup.exeMatrox Millennium video driver. Not required once drivers installed
    Xmgmtapimgmtapi.exeUnidentified malware
    XMHDOGStartmhdogst.EXEAdded by an unidentified VIRUS, WORM or TROJAN! A possibility is a trojan known as PENIS
    NMHINITMHINIT.EXEPart of the Cybermedia Clean Sweep package
    Xmhs3mhs3.exeAdded by the PWS-ALZ TROJAN!
    XMi7sft sdceb0yz.exeAdded by the RBOT.CWG WORM!
    XMi7sft sdceMNSQ.exeAdded by the RBOT.DMU WORM!
    XMi7sft sdcescorti.exeAdded by the RBOT.ELC WORM!
    XMickey Mouse Cereal[random filename].exeAdded by the RANKY.Q TROJAN!
    XMicosoft Data Corerunservice.exeAdded by the IRCBOT.BK WORM!
    XMicosoft Data Core stuffsvshosts.exeAdded by the RBOT.FZA WORM!
    XMicr Updatesoundblaster.exeAdded by the SDBOT.NP WORM!
    XMicr Update Systemupwin.exeAdded by the SDBOT.YS WORM!
    XMicr0s0ft Ms D0smsdx.exeAdded by the RBOT-AON WORM!
    XMicr0s0ft Upd4t4zsvchost32.exeAdded by the RBOT.ALF WORM!
    XMicrcoft Exploererspoolsal.exeAdded by the RBOT-AKK WORM!
    XMicrcoft Exploerersvchose.exeAdded by the RBOT-ASL WORM!
    XMicrcoft Updatspoolsae.exeAdded by the RBOT-AIB WORM!
    XMicrcoft Updatspoolsaex.exeAdded by the RBOT-AJM WORM!
    XMicrcoft UpdatInternet.exeAdded by the RBOT-ANA WORM!
    XMicrcsoft Certificate Servicescflmon.exeAdded by the RBOT-FWV WORM!
    XMicro CRC Protocolscrc32.exeAdded by a variant of the SDBOT WORM!
    XMicro Office[path to trojan]Added by the BANCBAN-QC TROJAN!
    XMicro Processappconf.exeAdded by an unidentified WORM or TROJAN!
    XMicro Updatedailin.exeAdded by the RBOT-ER WORM!
    NMicroangelo DesktopMuamgr.exeUsing MicroAngelo On Display, you can easily select the icon images that you prefer rather than the default icons displayed by Windows. On Display provides a consistent and elegant method to customize the icon display for almost every icon on your system
    NmicroAttuneDownloadatmdlusr.exeApplication Launcher, MS Office application. USR (US Robotics) modem auto updater. May be a sub-set of Attune
    UMicroBrewMicroBrew2.exeRelated to Bluebeam PDF printer support. Prints AutoCAD .dwgs to PDF's
    XMicroCQ0explorer.exeAdded by the LINEAGE-AK TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the Program Files folder
    UMicroDialleratdialler1.exePart of the Freeserve Connection Kit - changes the dial-up for Freeserve AnyTime if access problems are encountered
    XMicroedSoft ToolbarSmoked.exeAdded by the RBOT-ALN WORM!
    XMicrofinder lptt01mcf.exeRapidBlaster variant (in a "mcf" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
    XMicrofinder ml097emcf.exeRapidBlaster variant (in a "mcf" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
    XMicrofot Updatewinldx32.exeAdded by a variant of the RBOT WORM!
    XMicroft Exploererspoolsac.exeAdded by the RBOT-AMD WORM!
    XMicroft Update 32winssx.exeAdded by the RBOT-AQS WORM!
    XMicroLoad[random filename]Added by the DARBY WORM!
    XMicromedia Flash Updatewdfmrg.exeAdded by a variant of the SDBOT WORM!
    XMicromedia Flash Updatexptxt.exeAdded by the RBOT-GAB WORM!
    XMicrooft Timingpupdate.exeAdded by a variant of the RBOT WORM!
    XMICROSFT ANTIVIRUS UPDATE SUPPORT[random 10-letter filename].EXEAdded by the RBOT-AQA WORM!
    XMICROSFT ANTIVIRUS UPDATE SUPPORTMSGUPDATED.EXEAdded by the RBOT-APZ WORM!
    XMicrosft Conf 32msaconf.exeAdded by the RBOT.EYA WORM!
    XMicrosft Confige 32msaconfigurez.exeAdded by the RBOT.CLC WORM!
    XMicrosft Corporation Version 2001.12.4414comrel.exeAdded by a variant of the SDBOT TROJAN!
    XMicrosft Corporation Version 2002.12.2414comserv.exeAdded by a variant of the SLAPER TROJAN!
    XMICROSFT MX UPDATE SUPPORTtaskmngrs.exeAdded by the RBOT-AUZ WORM!
    XMICROSFT MX UPDATE SUPPORTwinmx32.EXEAdded by the IRCBOT-FD WORM!
    XMICROSFT RAMA UPDATE SUPPORT[random filename]Added by the RBOT-ASM or RBOT-AUW WORMS!
    XMICROSFT RAMA UPDATE SUPPORTMSN32.EXEAdded by the RBOT-AWJ WORM!
    XMICROSFT RAMA UPDATE SUPPORTmtakthmyn.EXEAdded by the RBOT-AUJ WORM!
    XMicrosft Security Monitor Processcmh.exeAdded by a variant of the SDBOT WORM!
    XMicrosft Security Monitor Processmssmppp.exeAdded by a variant of the SDBOT WORM!
    XMicrosft Security Monitor Processmssmpp.exeAdded by a variant of the RBOT-FUB WORM!
    XMicrosft Updtessarvice.exeAdded by a variant of the SDBOT WORM!
    XMicrosft Upgraed[random filename].exeAdded by a variant of the SDBOT WORM!
    XMicrosft Windows Adapter 5.1.3013[random filename]Detected by Kaspersky as the SMALL.HIT TROJAN! See here
    Xmicrosft windows updatesmwupdate32.exeAdded by a variant of the TOXBOT/CODBOT WORM!
    XMicrosof Valuenmatt.exeAdded by a variant of the RBOT WORM!
    XMicrosof Windows Hostsvhost32.exeAdded by the RBOT.ADY WORM!
    XMicrosof Winlog Hostwilogon32.exeAdded by the RBOT.XC WORM!
    XMicrosofot x386 System Monitorsystem32.exeAdded by the WOOTBOT.M WORM!
    Xmicrosoftsvchost.exeAdded by the ASTEF or RESPAN WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
    Xmicrosoftmicrosoft.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
    XMicrosoftwin32.exeAdded by the DARKMOON TROJAN!
    XMicrosoftiexplore.exeAdded by the QQROB-R TROJAN! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    XMicrosoftsvchost.exeAdded by the ADUYO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
    XMicrosoftwuauclt.exeAdded by the QQROB-AQ TROJAN! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup!
    XMicrosoftguard.exeAdded by a variant of the SDBOT WORM!
    XMicrosoftwcsntfy.exeAdded by the AGOBOT-AHT WORM!
    XMicrosoftssmss.exeAdded by the RBOT-FZF WORM!
    XMicrosoftlsass.ppfAdded by the RBOT-GAA WORM!
    XMicrosoftmsvchost.exeAdded by the RBOT-GAW WORM!
    XMicrosoftmixers.exeAdded by the AGOBOT-AHU WORM!
    XMicrosoftmsmsger.exeAdded by a variant of the SDBOT WORM!
    XMicrosoftMSUPDATE.exeAdded by an unidentified WORM or TROJAN!
    XMicrosoftradnom.exeAdded by the RBOT-GHO WORM!
    XMicrosoftrtvcscan.exeAdded by the RBOT-GGU WORM!
    XMicrosofttaskbar.exeAdded by a variant of the RBOT WORM!
    XMicrosoftupdater.exeAdded by the RBOT-GHP WORM!
    XMicrosoftwindl32.exeAdded by the SDBOT-DCZ WORM!
    XMicrosoftaim.exeAdded by the RBOT-GRY WORM! Note - this is not the popular AOL Instant Messenger utility
    XMicrosoftExplorerr.exeAdded by the IRCBOT-WG TROJAN!
    XMicrosoftkasperskyLive32.exeAdded by the RBOT-GRT WORM!
    XMicrosoftmsngerf.exeAdded by the RBOT-GLW WORM!
    XMicrosoftnetsrv.exeAdded by the RBOT-GOS WORM!
    XMicrosoftrundll.exeAdded by the RBOT-GSJ WORM!
    XMicrosoftWinSecUp.exeAdded by the RBOT-GPL WORM!
    XMicrosoftwsim32.exeAdded by the RBOT-GTL WORM!
    XMicrosoftwplayer.exeDetected by Kaspersky as the RBOT.DYU TROJAN! See here
    XMicrosoft Associates, Inc.iexplorer.exeAdded by a variant of the LOVGATE WORM!
    XMicrosoft (C) HTML Application host[random filename]Added by the RBOT-YB WORM!
    XMicrosoft (R) Windows Configuration Backup Servicesvchost.exeAdded by the RANKY.X TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in either a "config", "mapping" or "security" subfolder of the Winnt or Windows folder
    XMicrosoft (R) Windows DLL Loaderrundll32.exeAdded by the RANKY.W TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). This file is located in a "dll" subfolder of the Winnt or Windows folder
    XMicrosoft (R) Windows Network Latency Controller1.tmpAdded by a generic password stealer TROJAN - see here
    XMicrosoft (R) Windows Network Latency Controllernlc.exeAdded by a generic password stealer TROJAN - see here
    XMicrosoft (R) Windows Network Latency Controllersp2vc.exeAdded by a generic password stealer TROJAN - see here
    XMicrosoft (R) Windows Network Security Management Servicensms.exeAdded by the RANKY.LC TROJAN!
    XMicrosoft (R) Windows Protected Content Restoration Serviceservices.exeAdded by the AGENT.AGV TROJAN!
    XMicrosoft (R) Windows Protocol Deployment Manager[random].tmpAdded by an unidentified WORM or TROJAN!
    XMicrosoft (R) Windows TCP/IP Socket Driver[path to trojan]Added by the PROXY-DD TROJAN!
    XMicrosoft (R) Windows TCP/IP Socket Layerservices.exeAdded by the RBOT.ARM WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "winsock" sub-foler of the Windows or Winnt folder
    XMicrosoft (R) Windows Update Servicewuauclt.exeAdded by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup!
    XMicrosoft (R) Windows Vista/NT Runtime Compatibility Servicenrcs.exeAdded by the RANKY.X TROJAN!
    XMicrosoft .NET Confinguratormsnconf.exeAdded by an unidentified VIRUS, WORM or TROJAN!
    XMicrosoft 16Bit Updatewuapdate16.exeAdded by the RBOT.CZ WORM!
    XMicrosoft 64 Bit Runtime Updaterwupdt64.exeAdded by a variant of the RBOT WORM!
    XMicrosoft ActiveX Debugger NT[path to trojan]Added by the BANCOS-DO TROJAN!
    XMicrosoft Admin ProtocalMSADNIN.exeAdded by a variant of the RBOT WORM!
    XMicrosoft ADservice[random filename]Added by a variant of the RBOT WORM!
    XMicrosoft Agentmdss32.exeAdded by the KEYLOG-AG TROJAN!
    XMicrosoft Agentsvch0st.exeAdded by the VB-DRO WORM!
    XMicrosoft ALG32 Protocolalg32.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft ALGXP Protocolalg32.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft allmmall.exeWopla.ac malware variant
    NMicrosoft Announcement ListenerAnnclist.exeMS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
    XMicrosoft Ansti Updatemsie.exeAdded by the RBOT-LE WORM!
    XMicrosoft Anti-Spy[random filename]Added by a variant of the SDBOT WORM!
    XMicrosoft AntiSpywareBazzi.exeAdded by the AHKER.J WORM!
    XMicrosoft AntiSpywareKT06.pifAdded by the IRCBOT.GEN WORM!
    XMicrosoft AOL Instant MessengerMSAOL32.exeAdded by the RBOT-AAI WORM!
    XMicrosoft AOL32 Protocolaol32.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft Application Centermappc.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Application Managermsapl32.exeAdded by the BROPIA-AE TROJAN!
    XMicrosoft AUT UpdateMSlti32.exeAdded by the RBOT-X WORM!
    XMicrosoft AUT UpdateMSlti16.exeAdded by the RBOT.EB WORM!
    XMicrosoft Authority Servicelsass.exeAdded by the KALEL-D WORM! Note - this is not the legitimate lsass.exe process, which should not appear in Msconfig/Startup!
    XMicrosoft auto updatewinupdate.exeAdded by the BMBOT TROJAN!
    XMicrosoft Auto UpdateWINHLP16.EXEAdded by the RBOT.GY WORM!
    YMicrosoft auto updatewuauclt.exeAdded by the CULT-B TROJAN! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup!
    XMicrosoft Automatic Update Serivcemsautou.exeAdded by the RBOT-AOB WORM!
    XMicrosoft Automatic UpdaterExplorer.exeAdded by the RBOT-SG WORM! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System32 subfolder
    XMicrosoft AutoUpdatersvhost.exeAdded by the RBOT.QG WORM!
    XMicrosoft Bool ValueMV2.exeAdded by a variant of the RBOT WORM!
    XMicrosoft boot system cfg32actboost.exeAdded by the BROPIA.R WORM!
    UMicrosoft Broadband NetworkingMSBNTray.exeMicrosoft Broadband Networking Tray Application
    XMicrosoft Browser ServicesBrwsr32.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft Browser ServicesBrwsr64.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft Cab Managerexec.exeAffilred adware
    XMicrosoft Cab Managercab.exeAdded by the DELF-JJ TROJAN!
    XMicrosoft Calculatorcalc.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft checkerMsPMSPTv.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Clientmshost.exeAdded by the RBOT-AND WORM!
    XMicrosoft Client Pcspoolsrv.exeAdded by the RBOT-AQM WORM!
    XMicrosoft Client/Server Runtime Server Subsystemcsrs.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    XMicrosoft Client/Server Runtime Server Subsystemcsrssa.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    XMicrosoft Command Linewincmd.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Conf Ldrsysconf.exeAdded by a variant of the SDBOT TROJAN!
    XMicrosoft ConfgKeyswurmgrd32.exeAdded by the RBOT-ARX WORM!
    XMicrosoft Configmsconf.exeAdded by the RBOT.PV WORM!
    XMicrosoft ConfigMSCONF.EXEAdded by the RBOT-LG WORM!
    XMicrosoft Config 32msconfigx32.exeReported as the MSCONFIGX32 TROJAN! Possible Rbot variant
    XMicrosoft Config 32bitmscnfg32.exeAdded by the RBOT-Z WORM!
    XMicrosoft Config Fileconfig.exeAdded by the KILLFILES.GR TROJAN! This is malware that will attempt to delete all system dlls!
    XMicrosoft Config Loadermsconfig32.exeAdded by the AGOBOT.XX WORM!
    XMicrosoft Configoration Servicemsconfigs.exeAdded by the RBOT-ETT WORM!
    XMicrosoft Configs 32msgconfigrs.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Configuration 35microsot1.exeAdded by an unidentified TROJAN!
    XMicrosoft Configure 32msgconfigre.exeAdded by a variant of the GAOBOT/AGOBOT WORM!
    XMicrosoft Connection Manager Monitorcmmon.pifAdded by the RBOT-AKV WORM!
    XMicrosoft Control Centercrtl.exeAdded by the RBOT-VX WORM!
    XMicrosoft Core SupportMSxUP32.exeAdded by the RBOT-ANR WORM!
    XMicrosoft Core Support[random filename]Added by a variant of the RBOT TROJAN!
    XMicrosoft Corp SQL Certificatessqlcer.exeAdded by the ZYBOT-C WORM!
    XMicrosoft Corp SSL Certificateswindowz.exeAdded by the RBOT-GCZ WORM!
    XMicrosoft Corp TLS Certificatesmsauth.exeAdded by the RBOT-GAC WORM!
    XMicrosoft Corp Updateswupdates.exeAdded by the RBOT-AUU WORM!
    XMicrosoft Corporaticn SQL Handlersqlhandler.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Corporation[random filename]Added by various VIRUSES, WORMS & TROJANS!
    XMicrosoft Corporationjview.exeAdded by the RBOT-AOD WORM!
    XMicrosoft Corporation Svchost Servicemssvc.exeAdded by a variant of the SDBOT WORM! See here
    XMicrosoft Corporation Svchost Servicemswsc.exeAdded by the AGENT.MAB TROJAN!
    XMicrosoft Corporation SYM monitormssym.exeAdded by the RBOT-GDB WORM!
    XMicrosoft CP Web Managerwebcp.exeAdded by the IRCBOT.HP TROJAN!
    XMicrosoft CPU Over Heat ManagerCPU.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft CPXP Protocolcpxp.exeAdded by the RBOT.ATP WORM!
    XMicrosoft Critical Servicessvhhost.exeAdded by the AGOBOT-AJA WORM!
    XMicrosoft Crs Fix Servwincrs.exeAdded by the SDBOT.BWF WORM!
    XMicrosoft CRT Monitor Managercrtmon.exeDetected by Trend Micro as the ROBOTON.A WORM! See here
    XMicrosoft CSRSS Servicensmscrs.exeAdded by the RBOT-BPT WORM!
    XMicrosoft CSRSS32 Protocolcsrss32.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    XMicrosoft CSRSS386 Protocolcsrss386.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft Cvrtmscvrt32.exeAdded by an unidentified VIRUS, WORM or TROJAN!
    XMicrosoft Data Helpercihost.exeMalware, possibly a variant of the LINST TROJAN
    XMicrosoft Data Machinecsdata32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Database Handlermssql32.exeAdded by the RANDEX.AX WORM!
    XMicrosoft Datalog Applicationmsdata.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft DDE Controlwupades.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft DDEs ControlErun.pifAdded by the RBOT-AMU WORM!
    XMicrosoft Debug Servicedbgbgr.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Decryption TechnologyMsfenoe.exeAdded by the SPYBOT-DG WORM!
    XMicrosoft Desktop Managermsdesk32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Deviexplorer32.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    XMicrosoft Development Debuggermsdev.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Development Servicesmsdevelop.exeAdded by the RBOT-FWS WORM!
    XMicrosoft Device Managermsdevmgr32.exeAdded by the LATEDA.B TROJAN!
    XMicrosoft Device Managermscmtl32.exeDetected by Kaspersky as the AGENT.BMQ TROJAN! See here
    XMicrosoft Device Managersvcswin.exeAdded by the IRCBOT-YH TROJAN!
    XMicrosoft Diagnostic[random filename]Added by the ACEBOT TROJAN!
    XMicrosoft Diagnosticmsdiag32.exeAdded by the RBOT-UC WORM!
    XMicrosoft Digital Clockmsclock.exeAdded by the NACKBOT-D WORM!
    XMicrosoft Digital Cryptorsmdigits.exeAdded by the SDBOT.LM WORM!
    XMicrosoft DirectXSpoolserv.exeAdded by the DINFOR WORM!
    XMicrosoft DirectXrasmngr.exeAdded by a variant of the RBOT WORM!
    XMicrosoft DirectXPDSched.exeAdded by the SDBOT.CN WORM!
    XMicrosoft DirectXwuamgrd.exeAdded by the SDBOT.MY WORM!
    XMicrosoft DirectXtime123.exeAdded by the SDBOT.MD WORM!
    XMicrosoft Directxdirectxat.exeAdded by the SDBOT-BXF WORM! Note - disables autostart for the SharedAccess service and deactivates the Microsoft Internet Connection Firewall (ICF)
    XMicrosoft Directx clickdirectxclick.exeAdded by a variant of the RBOT-GHT WORM!
    XMicrosoft Directx clicksdirectxclickers.exeAdded by the RBOT-GHT WORM!
    XMicrosoft Directx pushdirectxpushup.exeAdded by a variant of the RBOT-GHT WORM!
    XMicrosoft Directxspdirectxbt.exeAdded by a variant of the RBOT-GHT WORM!
    XMicrosoft Directxspnewdirectxnew.exeAdded by a variant of the RBOT-GHT WORM!
    XMicrosoft DirktorWin[random filename]Added by the SPYBOT.GEN3 TROJAN!
    XMicrosoft Disk Scannerscansdisk.exeAdded by the WOOTBOT.DT WORM!
    XMicrosoft DLLfumeta.exeAdded by the RBOT-AUG WORM!
    XMicrosoft Dllrunapidll.exeAdded by the RBOT-GRG WORM!
    XMicrosoft DLL Authentificationdllsecure.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft DLL ExtensionsSystemDll.exeAdded by the RBOT-ADV WORM!
    XMicrosoft dll Host Servicewkssr.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft DLL Host Servicedllmemhost.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft DLL Host Servicesvcdllhst.exeAdded by the AGENT.EAK TROJAN!
    XMicrosoft dll Host Servicesvchost.exeDetected by Kaspersky as the RBOT.BMS WORM! See here. Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
    XMicrosoft DLL Librarywinlib32.exeAdded by the ATNAS.A WORM!
    XMicrosoft Dll Managementwindll.exeAdded by the RBOT-MT WORM!
    XMicrosoft Dll Managermicrosoft32dll.exeDetected by Trend Micro as the SHEUR.LH TROJAN! See here
    XMicrosoft DLL Monitordllmon32.exeDetected by Trend Micro as the AGENT.WP WORM! See here
    XMicrosoft DLL Monitordllmon64.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft DLL Monitordllmonitor.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft Dll Printer Managerdllpt.exeAdded by the SDBOT.BIH WORM!
    XMicrosoft DLL Serviceservicedll.exeDetected by Trend Micro as the RCBOT.OX TROJAN! See here
    XMicrosoft DLL Servicesvcdll.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft DLL Sourcedllsrc.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft DLL Verifierfile.exeAdded by the RBOT-AED WORM!
    XMicrosoft DLL Verifierchkfile.exeAdded by the RBOT-AOC WORM!
    XMicrosoft DLL Verifiercsrssv.exeAdded by the RBOT-ATK WORM!
    XMicrosoft DLL Verifiermscon.exeAdded by the SDBOT.EAH WORM!
    XMicrosoft DLL Verifierwinavguard.exeAdded by the SDBOT.AAD WORM!
    XMicrosoft DLLSet32dllset32.exeAdded by the RBOT.OZ WORM!
    XMicrosoft DNS Querymsdns.exeAdded by a variant of the WOOTBOT WORM!
    XMicrosoft DNSxmdnex.exeAdded by the DELBOT-AI WORM!
    XMicrosoft Documentkrisp.exeAdded by the SDBOT-RQ WORM!
    XMicrosoft Domain Controllermstc.exeAdded by the NUGACHE.A WORM!
    XMicrosoft Driverfaet.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Driver Controlwindrv.exeAdded by the SDBOT.FW WORM!
    XMicrosoft Driver Managermswindrv.exeAdded by the FORBOT-EZ WORM!
    XMicrosoft driver updateMshome.exeAdded by the SDBOT.BL WORM!
    XMicrosoft DriversWSconf.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft ErgoPackwserb32.exeAdded by the RBOT-RI WORM!
    XMicrosoft EV32 ServiceMSev32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Event EngineEvtEngn.exeAdded by the RBOT-XV WORM!
    XMicrosoft Excelmsexcel.exeAdded by the RBOT-TQ WORM!
    XMicrosoft Excellwuamngr32.exeAdded by the RBOT-QH WORM!
    XMicrosoft Executingmicrosoft.exeAdded by the AGOBOT.UV WORM!
    XMicrosoft Explorersvapache.exeAdded by the RBOT-VR WORM!
    XMicrosoft Explorerexplorer.scrAdded by the RBOT-ADH WORM!
    XMicrosoft Explorerexplorer.pifAdded by the SDBOT-ACX WORM!
    XMicrosoft Explorerexplorer.exeAdded by the POEBOT-LY WORM! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    XMicrosoft Explorer Servicemsexplore.exeDetected by Kaspersky as the IRCBOT.AYB TROJAN! See here
    XMicrosoft explorer Updateinternal.exeAdded by an unidentified WORM or TROJAN!
    XMicrosoft Explorer2system.exeAdded by the IRCBOT.BS TROJAN!
    XMicrosoft Explorer2nome.exeAdded by the RANDEX.AA WORM!
    XMicrosoft Explorer2bitchbot.exeAdded by the SDBOT.EV WORM!
    XMicrosoft EXPLOREXP Protocolexplorexp.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft Featuresms32cfg.exeAdded by the RBOT.HO WORM!
    XMicrosoft Featuresmsie.exeAdded by a variant of the RBOT WORM!
    XMicrosoft File Demand Managerwmgrdf.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Find FastFindfast.exeComplete utter waste of space! Part of MS Office - searches disk drives for Office file types and creates an index to make opening them easier
    XMicrosoft Firewallfirewallsp2.exeAdded by the RBOT-MC WORM!
    YMICROSOFT FIREWALL CLIENTISATRAY.EXEMS Internet Security and Acceleration Server - see here
    XMicrosoft FixUppevblbvr.exeAdded by the RBOT.DWK WORM!
    XMicrosoft FixUpwnpzjpuw.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Gamesgamemanager.exeAdded by the SPYBOT.AHQ WORM!
    XMicrosoft Generic Update Managerwupdate.exeAdded by the RBOT-AWC TROJAN!
    XMicrosoft Genetic Procresssvchost.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Genuine Logonmsnmsg.exeAdded by the IRCBOT-XH WORM!
    XMicrosoft Genuine Logonsvchost.exeAdded by the SDBOT.EXT WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
    XMicroSoft Getway Dire[random filename]Detected by Trend Micro as the IRCBRUTE.AM WORM! See here
    XMicroSoft Getway mqbol[12 random letters].exeDetected by Trend Micro as the RBOT.GBA WORM! See here
    XMicrosoft Gina V EncryptionMSGINAV.EXEAdded by an unidentified VIRUS, WORM or TROJAN!
    NMicrosoft Greetings RemindersMHPRMIND.EXEMicrosoft Home Publishing greetings reminder
    NMicrosoft Greetings Workshop ReminderGwremind.exeYou really want to be reminded about somebody's birthday at the expense of resources?
    NMicrosoft Greetings  ReminderMHPRMINF.EXEYou really want to be reminded about somebody's birthday at the expense of resources?
    XMicrosoft HDCP for NTmsdhcp.exeAdded by a variant of the RBOT WORM!
    XMicrosoft HDCP for NT and Win9xmsdhcprs.exeAdded by a variant of the PEERBOT WORM!
    XMicrosoft Helpsvh0st.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft Help Supportmshelp32.exeAddded by the KELVIR-BF WORM!
    XMicrosoft Help SVCmsnmngr.exeAdded by the SDBOT-PQ WORM!
    XMicrosoft Help Systemmshelp32.exeCoolWebSearch parasite variant
    XMicrosoft Host Protocolsvhost.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Hosting ServiceWINHOSTING.EXEAdded by the RBOT.AEV WORM!
    XMicrosoft Hosts ServiceIsass.exeAdded by a variant of the RBOT WORM!
    Umicrosoft hotmail monitormshotmon.exeAdded by the MYTOB-FL WORM!
    XMicrosoft hren1mmhren1.exeAdded by a variant of the AGENT.IWW TROJAN!
    XMicrosoft Hyptertext Helpermshtha.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft IDCNmshe1p.exeAdded by an unidentified TROJAN!
    XMicrosoft IEIexplore.exeAdded by the FORBOT-AG WORM! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    XMicrosoft IE Execute shellIEExec.exeAdded by the ALADINZ.N TROJAN!
    XMicroSoft IE SasserISASS.EXEAdded by the SDBOT.MX WORM!
    XMicrosoft IISsyshost.exeAdded by the FRANCETTE WORM!
    XMicrosoft IIS[filename]Added by the FRANCETTE-S WORM!
    XMicrosoft Inc.iexplorer.exeAdded by a variant of the LOVGATE WORM!
    XMicrosoft Incroporatemfs.exeAdded by the RBOT-ANF WORM!
    XMicrosoft Inet Xp..teekids.exeAdded by the BLASTER.C WORM!
    XMicrosoft Information Checkmicrosoft.exeAdded by the IRCBOT.AUH TROJAN!
    XMicrosoft Install Shield Servicesrundll64Added by the RBOT-FSH WORM!
    XMicrosoft Installshieldnundll32.exeAdded by the AGOBOT-AHZ WORM!
    XMicrosoft Instant Messengermsngmsngr32.exeAdded by the SPYBOTER.GEN TROJAN!
    XMicrosoft Int ServiceMsIntSrv.exeAdded by a variant of the RBOT WORM!
    UMicrosoft Intellitype Prospeedkey.exeAdditional keyboard shortcuts on MS programmable keyboard
    XMicrosoft Internal AntiVirus SystemsdIlhost.exeAdded by the RBOT-AEV WORM!
    XMicrosoft Internetexpl0rer.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft Internetwindows32.exeAdded by the SDBOT-F WORM!
    XMicrosoft Internetwincfg16.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Internet Acceleration Utilityiau.exeEasySearch adware
    XMicrosoft Internet Acceleration Utility[path to file]Added by the AGENT-CX TROJAN!
    XMicrosoft Internet Acceleration Utility[path to trojan]Added by the SMUTSRCH-A TROJAN!
    XMicrosoft Internet Antivirus Protectionantivirus.exeDetected by Kaspersky as the IRCBOT.BSK TROJAN!
    XMicrosoft Internet Dumping Protocolinetdump.exeDetected by Kaspersky as the IRCBOT.BLL TROJAN! See here
    XMicrosoft Internet Expiiexplorer.exeAdded by the RBOT-KX WORM!
    XMicrosoft Internet Exploreriexplore.exeAdded by the POEBOT-J WORM! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    XMicrosoft Internet Exploreriexplorer.exeAdded by the SDBOT-XN WORM!
    XMicrosoft Internet Explorercrsys32.exeAdded by the RBOT.UZ WORM!
    XMicrosoft Internet Explorermovies.exeAdded by the BANCOS-DZ TROJAN!
    XMicrosoft Internet Explorersvzhost.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Internet Explorermccagent.exeAdded by the DLOADER-UD TROJAN!
    XMicrosoft Internet Explorersysini.exeAdded by the DELF-LN TROJAN!
    XMicrosoft Internet Explorersvchost.exeAdded by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "drivers" subfolder
    XMicrosoft Internet ExplorerlEXPLORE.EXEAdded by the RBOT-AMM WORM! Note - the executable is spelt with a lower case "L" rather than an lower or upper case "i" which is the case with Internet Explorer
    XMicrosoft Internet Explorer Managerie.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft Internet Explorer Updateieupdate.exeDetected by Trend Micro as the SHEUR.MH WORM! See here
    XMicrosoft Internet Firewallfirewall.exeDetected by PCTools as the IRCBOT.BMD TROJAN! See here
    XMicrosoft Internet Firewall ManagerGMT16.exeAdded by the RANDEX.AT WORM!
    XMicrosoft Internet Firewall Updateupdater.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft Internet ServicesSmss32.exeAdded by the RBOT.MS WORM!
    XMicrosoft Internet Syncinginetsync.exeDetected by Kaspersky as the IRCBOT.BLL TROJAN! See here
    XMicrosoft Intrenet Explorergoaw.pifAdded by the RBOT-API WORM!
    XMicrosoft Intrenet ExplorerSoundsyst.exeAdded by the RBOT-AQU WORM!
    XMicrosoft Intrenet Explorercnsg.pifAdded by the RBOT-ARO WORM!
    XMicrosoft Intrenet Explorerwcumrg.exeAdded by the SDBOT-AFD WORM!
    XMicrosoft IPCsystem.exeAdded by the NULLBOT TROJAN!
    XMicrosoft IPCsvshost.exeAdded by an unidentified VIRUS, WORM or TROJAN!
    XMicrosoft IT Updatewin64.exeAdded by the RBOT.GA WORM!
    XMicrosoft IT Update[random filename]Added by a variant of the RBOT WORM!
    XMicrosoft IT UpdateIEserv.exeAdded by a variant of the RBOT WORM!
    XMicrosoft IT Updatemsupdate.exeAdded by a variant of the RBOT WORM!
    XMicrosoft IT Updatewinn43.exeAdded by a variant of the RBOT WORM!
    XMicrosoft IT Updatesvchsst.exeAdded by the RBOT-DH WORM!
    XMicrosoft IT Updatewin43.exeAdded by the RBOT-SA WORM!
    XMicrosoft IT Updatewindows.exeAdded by the RBOT-GL WORM!
    XMicrosoft IT Updatewinsyst32.exeAdded by the RBOT-FC WORM!
    XMicrosoft IT UpdateRhost32.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft Java Virtual Machinewinscr32.exeAdded by a variant of the WOOTBOT WORM!
    XMicrosoft Java Virtual MachineMsConfiG.exeAdded by the FORBOT-DV WORM!
    XMicrosoft Java Virtual Machinemsjvm.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Java Virtual Machinejavavm.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Java Windows Update[filename]Added by the RBOT-DZ WORM!
    XMicrosoft JavaVMmsjarun.exeAdded by the RBOT-JW WORM!
    XMicrosoft KernelWindows_kernel32.exeAdded by the NETSKY.AE WORM!
    XMicrosoft Keyboard Enhance 2.0.iasrecst.exeAdded by the BCKDR-QIL TROJAN!
    XMicrosoft Keyboard Enhance V2.0iasrecst.exeDetected by F-Prot as the DOWNLOADER2.AILI TROJAN!
    XMicrosoft LAN32 ProtocollanXp.exeAdded by the RBOT-SS WORM!
    XMicrosoft Lmhosting Servicelmhosts.exeAdded by the RBOT-RC WORM!
    XMicrosoft Locals 332[random filename]Added by the RBOT-KU WORM!
    UMicrosoft Location FinderLocationFinder.exeMicrosoft Location Finder "is a client-side application that turns a regular WiFi enabled laptop, Tablet or PC into a location determining device without the addition of any separate hardware"
    XMicrosoft Loginwinlogin.exeAdded by the RBOT-AJP WORM!
    XMicrosoft LSA layerMSLSA32.exeAdded by the RBOT-AKZ WORM!
    XMicrosoft Lsass CenterIsass.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Lsass Centertelecomes.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Lsass Managerlsass.exeAdded by a variant of the SDBOT WORM! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
    XMicrosoft Lsass Servicewintcp32.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft LSASS386 Protocolscvhost32.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft LV[path to file]Added by the BDL TROJAN!
    XMicrosoft Machinewinjava.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    XMicrosoft machineblah.exeAdded by a variant of the RBOT WORM!
    XMicrosoft machinesvchost.exeDetected by Kaspersky as the RBOT.AEU TROJAN! See here. Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
    XMicrosoft Machine Scriptiexplorersis.exeAdded by the RBOT-CMH WORM!
    XMicrosoft Macro Protection SubSsymsacroprots386.exeAdded by the RBOT-KE WORM!
    XMicrosoft Macro Protection Subsystemsmsmacroprotxz.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft Macro Protection SubsystemsMsmacroprot32.exeAdded by the RBOT.KN WORM!
    XMicrosoft Manage Servicessychost.exeDetected by Trend Micro as the SLENFBOT.AD WORM! See here
    XMicrosoft Managementlmas.exeAdded by the FORBOT-CZ WORM!
    XMicrosoft Management Consolelssas.exeEasySearch adware
    XMicrosoft Management Console[path to trojan]Added by the SMUTSRCH-A TROJAN!
    XMicrosoft Management Consolelssas1.exeAdded by the DLOADR-AWD TROJAN!
    XMicrosoft Managermsmanager.exeAdded by the MYTOB.LF WORM!
    XMicrosoft Map PCmappc.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Mapped PCmappedpc.exeAdded by a variant of the RBOT WORM!
    XMicrosoft mediawinmplayers.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft Media Managermedman.exeAdded by the RBOT.EUZ WORM!
    XMicrosoft Media player 9msmedia32.exeAdded by the RBOT-ADO WORM!
    XMicrosoft media servicesIassd.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    XMicrosoft media serviceswinmplayer.exeAdded by the RBOT.ZO WORM!
    XMicrosoft MediaScopewinmes.exeAdded by the RBOT-XU WORM!
    XMicrosoft Memory Dumping Protocolmemdump.exeDetected by Kaspersky as the IRCBOT.BJK TROJAN! See here
    XMicrosoft Memory Flow Cycleflowcycle.exeDetected by PCTools as the IRCBOT.WAD TROJAN! See here
    XMicrosoft Memory Flow Cycleflowcycles.exeDetected by Kaspersky as the WAREZOV.AAK WORM! See here
    XMicrosoft Message Machinemsmesg32.exeAdded by the SPYBOT.BI WORM!
    XMicrosoft Messenger Management Controlsmsmgmctl.exeAdded by the RBOT-APA WORM!
    XMicrosoft messenger sdmsngersd.exeAdded by an unidentified TROJAN!
    XMicrosoft Messenger Servicemsmsg32.exeAdded by the RBOT.BOK WORM!
    XMicrosoft Messenger XPMSMSN32.exeAdded by the RBOT-ZP WORM!
    XMicrosoft MicroP Protocolwdgmr32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Movie MakerMmaker.exeAdded by the IRCBOT.C TROJAN! Note that this is not a valid Microsoft program
    XMicrosoft MSGPLUS32 Protocolmsgplus32.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft MSN Messengermsnmnsgr.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft MSNGR32 Protocolmsngr32.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft msnserumsnseru.exeAdded by the RBOT-APB WORM!
    XMicrosoft MsnSTmsnst32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft MSUPDATESpoolSvc.exeAdded by the SXTB-A TROJAN!
    XMicrosoft Neser Experiencenese.exeAdded by the RBOT-YH WORM!
    XMicrosoft NetMeeting Associates, Inc.NetMeeting.exeAdded by a variant of the LOVGATE WORM!
    XMicrosoft Netviewgesfm32.exeAdded by the RANDEX.C WORM!
    XMicrosoft Netviewmssvc32.exeAdded by an unidentified VIRUS, WORM or TROJAN!
    XMicrosoft Netview Component v5.1msnv32.exeAdded by the RANDEX.F WORM!
    XMicrosoft Networkmsnet.exeAdded by the MOCKBOT.A WORM!
    XMicrosoft NetworkNetworksystem.exeAdded by the SDBOT-AAI WORM!
    XMicrosoft Network Daemon for Win32Netd32.exeAdded by the SDBOT.R TROJAN!
    XMicrosoft Network Hostsvc0host.exeAdded by the SDBOT-AEN WORM!
    XMicrosoft Network Neighbourhoodnetworknbh.exeAdded by the RBOT.DMN WORM!
    XMicrosoft Network Services Controllermmsvc32.exeAdded by the NANPY-A WORM!
    XMicrosoft Networking Agent For SP2msnac32.exeAdded by the SPYBOT.PEN WORM!
    XMicrosoft Nod32 Servicenood32.exeAdded by the RBOT.EJP WORM!
    XMicrosoft Norotn Anti Virusmnhpot.exeAdded by the RBOT-GRO WORM!
    XMicrosoft Norton Antivirusnorton.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft NotePadnotepad.exeAdded by a variant of the RBOT WORM!
    XMicrosoft NT Driversntdrv.exeAdded by the SDBOT.AJN TROJAN!
    XMicrosoft NT Updatewinexec32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Nvidia Videonvidia.exeAdded by a variant of the SDBOT WORM!
    NMicrosoft OfficeOsa.exeApplication which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
    NMicrosoft OfficeMsoffice.exeAlternative shortcuts to the Start -> Programs way of running applications installed as part of MS Office. Some people prefer it but a better way is to create Desktop Shortcuts if you want access these programs quickly
    XMicrosoft OfficeMSMSGR.exeAdded by the GAOBOT.BB WORM!
    NMicrosoft OfficeOsa9.exeApplication which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
    XMicrosoft Officelserv.exeAdded by the SDBOT.MH WORM!
    XMicrosoft OfficeMicrosoft Office.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
    XMicrosoft Officemsoicons.exeAdded by the RBOT-ZI WORM! - NOTE - do no confuse with the legitimate Msoicons.exe file described here. The latter wil not be listed among your startups!
    XMicrosoft OfficeNxcao.exeAdded by the RBOT-ZE WORM!
    XMicrosoft Officenxcxtpr.exeAdded by the RBOT-YG WORM!
    XMicrosoft Officesvxhost.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Officemsoffice32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Officemsoff.exeAdded by the RAKER-C TROJAN!
    XMicrosoft Officemicrosoft.exeAdded by the BANKER-VF TROJAN!
    XMicrosoft Officemsvcp.exeAdded by the AGENT-XK TROJAN!
    XMicrosoft Officemsmsgr.exeAdded by the GAOBOT.BB WORM!
    XMicrosoft Officemdm.exeAdded by the IBOT-A TROJAN! Note - this is not the Machine Debug Manager (also known as MDM7) which shares the same filename
    NMicrosoft Office Fast CacheFastboot.exePart of MS Office 95 (v7.0). According to this it improves the performance. Most likely a predecessor of MS Find Fast and can be disabled
    XMicrosoft Office Monitoralg2k.exeAdded by the SDBOT-CZO WORM!
    XMicrosoft Office Monitoraql32.exeAdded by the RBOT-GCY TROJAN!
    UMicrosoft Office OneNote 2003 Quick LaunchONENOTEM.EXEONENOTEM.EXE is a part of the note taking program that ships with Microsoft Office 2003. It's required for the side note windows to work
    XMicrosoft Office Quick Launcheriau1.exeAdded by the DLOADR-AWD TROJAN!
    NMicrosoft Office Shortcut BarMsoffice.exeAlternative shortcuts to the Start -> Programs way of running applications installed as part of MS Office. Some people prefer it but a better way is to create Desktop Shortcuts if you want access these programs quickly
    XMicrosoft Office Startwinupdates.exeAdded by the GAOBOT.BC WORM!
    NMicrosoft Office StartupOsa.exeApplication which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
    NMicrosoft Office StartupOsa9.exeApplication which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
    XMicrosoft Office Studioscvhvst.exeAdded by the RANDEX.CST WORM!
    XMicrosoft OfficeXPofficeXP.exeAdded by the KILLAV.MA WORM!
    XMicrosoft Ofticemsmsgs.exeAdded by the IRCBOT.ALT WORM! Note - not to be confused with msmsgs.exe, the well known MSN Instant Messaging application!
    XMicrosoft OpeionsIEXwe.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Outlook Express Protocolsvchst.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Patch Updatebootini.exeAdded by the RBOT-FMN WORM!
    XMicrosoft PC Health Remote Assistance File Open & Save controlssfrcdlg32.exeAdded by the RBOT-AVY WORM!
    XMicrosoft PCHealth32[path to file]Added by the NICE-A TROJAN!
    XMicrosoft PCHealth32NDDENB.exeAdded by the PWSYAHOO-A TROJAN!
    XMicrosoft PCI Managermspci.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Personal Firewallsbakw.exeAdded by the RBOT-KS WORM!
    XMicrosoft Problem Doctorwindr128.exeAdded by the SMALLTRO.EF TROJAN!
    XMicrosoft Problem Doctorwindr32.exeAdded by a variant of the SMALLTRO.EF TROJAN!
    XMicrosoft Problem Doctorwindr64.exeAdded by a variant of the SMALLTRO.EF TROJAN!
    XMicrosoft Proc Driver32msprc.exeAdded by a variant of the WOOTBOT WORM!
    XMicrosoft Procedure CallMSPCALL.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Process Managerprocess32.exeAdded by the CHECKOUT WORM! See here
    XMicrosoft Profile Managerprofile.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft PSTCP32 Datapstcp32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft QMGRmsnqmgr.exeAdded by the IRCBOT-S TROJAN!
    XMicrosoft RDLLsysconf32.exeAdded by a variant of the SDBOT TROJAN!
    XMicrosoft Redirect[path to file]Added by the BANKER-FW TROJAN!
    XMicrosoft Redirectsysten.exeAdded by the BANCOS-FO TROJAN!
    XMicrosoft Regestry Edit Managerregedit.exeDetected by Trend Micro as the SHEUR.HC WORM! See here
    XMicrosoft Regestry Managerregedit32.exeAdded by a variant of the IRCBOT.ARD WORM!
    XMicrosoft Regestry Managerregistry32.exeAdded by the IRCBOT.ARD WORM!
    XMicrosoft Registrosvchostt.exeAdded by the BANCOS-DH TROJAN!
    XMicrosoft Registrycsrse.exeAdded by the RBOT-PC WORM!
    XMicroSoft Remote Secure ServiceMSRSS.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Restorescrgrd.exeAdded by the SPYBOT.BR WORM!
    XMicrosoft Router Managerlinksys.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft Router Managerrouter.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft Rundllwindos.exeAdded by the SDBOT-WF WORM!
    XMicrosoft RuntimeCfgDll32.exeAdded by the RANDEX.BD WORM!
    XMicrosoft Safe Mode Managersafemode.exeDetected by Trend Micro as the IRCBOT.HM TROJAN! See here
    XMicrosoft Scanregmicrosoftscanreg.exeAdded by the FRANRIV.A WORM!
    XMicrosoft SCVHOST32 Protocolscvhost32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft sddcE Contoltaskmnegr.exeAdded by the RBOT-AUM WORM!
    XMicrosoft sdk tempsdktemp.exeAdded by the RBOT-ANP WORM!
    XMicrosoft SDKP3mswinsdq.exeAdded by the RBOT-ARY WORM!
    XMicrosoft Secure Messenger.NET Servicesecuritychk.exeAdded by the SDBOT.VT WORM!
    XMicrosoft SecuritywinService.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Security Advisermsavsc.exeDetected by Kaspersky as the AGENT.ANQ TROJAN! See here
    XMicrosoft security advisermssadv.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft Security Centersavservices.exeAdded by the RBOT-ANU WORM!
    XMicrosoft Security Centerwcsntfy.exeAdded by the SDBOT.BYD WORM!
    XMicrosoft Security Controlersfxsecues.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Security GManagers[random filename]Added by a variant of the SDBOT WORM!
    XMicrosoft Security Hot Fix Updatemshotfix.exeAffilred adware
    XMicrosoft Security Managementwinnt.exeAdded by the RBOT-MQ WORM!
    XMicrosoft Security Managementwinserv.exeAdded by the RBOT-MJ WORM!
    XMicrosoft Security Managementwinamp.exeAdded by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player which resides in a "Winamp" subdirectory of the Program Files directory
    XMicrosoft Security Managementwuauct1.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Security Managementbling.exeAdded by the RBOT.XL WORM!
    XMicrosoft Security Managementsp2fix.exeAdded by the RBOT.UB WORM!
    XMicrosoft Security Managerwinamp.exeAdded by the RBOT WORM! Note - this is NOT the popular Winamp media player which resides in a "Winamp" subdirectory of the Program Files directory. This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    XMicrosoft Security Monitor Processmssmp.exeAdded by the RBOT-FUB WORM!
    XMicrosoft Security Monitor Processmnsmp.exeAdded by the RBOT-FUB WORM!
    XMicrosoft Security Monitor Processmsmp.exeAdded by a variant of the RBOT-FUB WORM!
    XMicrosoft Security Monitor Processmssm32.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft Security Panager[filename]Added by the RBOT-ANL WORM!
    XMicrosoft Security Panagers[random filename]Added by the RBOT-AIG WORM!
    XMicrosoft Security Panagerszzoboony.exeAdded by the RBOT-AOI WORM!
    XMicrosoft Security Processwininit.exeAdded by the RBOT-FKM WORM!
    XMicrosoft Security Systemmssecsys.exeAdded by the IRCBOT-WJ TROJAN!
    XMicrosoft Security Updatesecurity32.exeAdded by the DELF-JJ TROJAN!
    XMicrosoft Serverrserv.exeAdded by the AGOBOT.AVS WORM!
    XMicrosoft Server Applacationsmsnmsg.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Server Applacationswuauct1.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Server Applacationslsasss.exeAdded by the RBOT-AQQ WORM!
    XMicrosoft Server ApplacationsQ8See.exeAdded by the SPYBOT.GEN3 TROJAN!
    XMicrosoft Server Applacationscli.exeAdded by the RBOT-GAQ WORM!
    XMicrosoft Server ApplicationSound.exeAdded by the RBOT-NE WORM!
    Xmicrosoft server baselass.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Server Processsvhst32.exeAdded by the BCKDR-QHR TROJAN!
    XMicrosoft Servicemicrohost.exeAdded by the RBOT-LC WORM!
    XMicrosoft Servicewinsvc.exeAdded by the SPYBOT-DB WORM!
    XMicrosoft Servicerundll.exeAdded by the POPO-A WORM! Note - this is NOT the Windows system file of the same name as described here
    XMicrosoft Service 32mssvc32.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft Service 32sysddm32.exeDetected by Kaspersky as the SDBOT.AKC TROJAN! See here
    XMicrosoft Service Access ManagerAccess.exeAdded by a variant of the IRCBOT TROJAN! See here
    XMicrosoft Service Bootsboot.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft Service Controllerservices.exeAdded by the KALEL-D WORM! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
    XMicrosoft Service Disk Cycledisksave.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft Service DriversSystem.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Service DriversVSADNIM.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Service Execution Managerexecute.exeAdded by a variant of the IRCBOT TROJAN! See here
    XMicrosoft Service firewall Managerfirewall.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Service Host Manager32svchost.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft Service Host Processsvchost.exeAdded by the KRYNOS.B WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "Help" subfolder of the Winnt or Windows folder
    XMicrosoft Service Login Managerwinlogin.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft Service Managerservice32.exeAdded by a variant of the RBOT WORM! See here
    XMicrosoft Service Managerwinsvc.exeAdded by a variant of the RBOT WORM! See here
    XMicrosoft Service PackWindowsSP.exeAdded by the RBOT-RF WORM!
    XMicrosoft Service Pack2.1svchost2.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Serviceslsserv.exeAdded by an unidentified VIRUS, WORM or TROJAN!
    XMicrosoft Serviceslssrv.exeAdded by the RBOT.CW WORM!
    XMicrosoft Servicesservices.exeAdded by the ALETS TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
    XMicrosoft Serviceslsrv.exeAdded by the RBOT-BK WORM!
    XMicrosoft Servicessvshost.exeAdded by the ALETS.B TROJAN!
    XMicrosoft Servicesbsc32.exeAdded by the BDOOR-AW TROJAN!
    XMicrosoft ServicesSmss32.exeAdded by the RBOT-AD WORM!
    XMicrosoft Servicessvssshost.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Servicesmodule.exeAdded by the LAVITS WORM!
    XMicrosoft Servicesmsmpserv.exeDetected by Trend Micro as the IRCBOT.BKA TROJAN! See here
    XMicrosoft Services UnitdMSU32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Servicez Managerservicemgrz.exeAdded by the RBOT-ASN WORM!
    XMicrosoft Session Manager Subsystemsmss.exeAdded by the KALEL-D WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!
    XMicrosoft Setup Initializazionlocalhost.exeAdded by a variant of the IRCBOT TROJAN!
    NMicrosoft Sidewinder Game Controller SoftwareSWTRAY.EXEMS SideWinder game controller system tray icon. Available via Start -> Programs
    XMicrosoft Sinsupodjiwjf.exeAdded by the RBOT-DN WORM!
    XMicrosoft Softwaresysinfo33.exeAdded by the RBOT.LS WORM!
    Xmicrosoft software****.exe E255 [* = random char]Added by an unidentified WORM or TROJAN!
    XMicrosoft softwarecdaccess.exeAdded by the RBOT.ABK WORM!
    XMicrosoft Software Updatenmon.exeAdded by the RBOT.HZ WORM!
    XMicrosoft Sound Driversound32.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft Sound Technologywinsound.exeAdded by the RBOT-AGG WORM!
    NMicrosoft Sound Volume Toolmssvol.exeThis is a Blue version of the yellow speaker icon on the system tray and is used to edit advanced Sound Features that the MS DSS80 Speakers add. Should be accessible via Start -> Settings -> Control Panel
    XMicrosoft Soundssoundman.exeAdded by the RBOT-GCI WORM!
    XMicrosoft SourceSafecsrss.exeAdded by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
    XMicrosoft SpA Servicemsapps.exeAdded by the RBOT-VI WORM!
    XMicrosoft SpA Servicewin32.exeAdded by the RBOT.ATS WORM!
    XMicrosoft SpA ServiceWinupd32.exeAdded by the RBOT.LT WORM!
    XMicrosoft Special offerinfoebay.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Spool ** Servicespool**.exeAdded by a variant of the IRCBOT TROJAN - where ** represents a 2 digit number
    XMicrosoft Spool Server for Win32spoolsrv.exeAdded by the RANDEX.H WORM!
    XMicroSoft ssas3s1SADASDA.exeDetected by PCTools as the RBOT.URF WORM! See here
    XMicrosoft SSISVRI32 Protocolssisvri.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft Standard Executions Librarywin32lib.exeAdded by the RBOT-AUK WORM!
    XMicrosoft standard protectorwinsocks5.exeAdded by the SMALL.CF TROJAN!
    XMicrosoft standard protector[path to trojan]Added by the STOX-C TROJAN!
    XMicrosoft startupwmpIayer.exeAdded by the IRCBOT.ACI TROJAN!
    XMicrosoft Stuff you knowwinslogin.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Sum32sum32.exeAdded by the RBOT-YW WORM!
    XMicrosoft Supportsys32ms.exeAdded by the RBOT-AHI WORM!
    Xmicrosoft supportsvchostt.exeAdded by the AGOBOT.AWN WORM!
    XMicrosoft SVCmssvc.exeAdded by the BIFROSE-UQ TROJAN!
    XMicrosoft Svchost local serviceswinoem.exeAdded by the RBOT-FPE WORM!
    XMicrosoft Svchost local serviceswinoem.exeAdded by the RBOT-FPE WORM!
    XMicrosoft Svchost local servicesnzm23.exeAdded by the RBOT-GMC WORM!
    XMicrosoft Svchost local servicesmsnserver.exeAdded by the RBOT-GPM WORM!
    XMicrosoft Syn ManagerManager.exeAdded by the SDBOT.BEF WORM!
    XMicrosoft Synchronization Managerasgard.exeAdded by the SDBOT-AEA WORM! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    XMicrosoft Synchronization Managerbot.exeAdded by the SDBOT.IH WORM!
    XMicrosoft Synchronization Managernetscape.exeAdded by the RANDEX.AE WORM!
    XMicrosoft Synchronization Managerslhost.exeAdded by the SDBOT.YH WORM!
    XMicrosoft Synchronization Managersvhost.exeAdded by the SDBOT-PY WORM!
    XMicrosoft Synchronization ManagerWinLoginnn.exeAdded by the SPYBOT.FO WORM!
    XMicrosoft Synchronization Managerwinupdate.exeAdded by the SDBOT.ER WORM!
    XMicrosoft Synchronization ManagerxXx.exeAdded by the SDBOT-KZ WORM!
    XMicrosoft Synchronization Manager___synmgr.exeAdded by the MASLAN.A or MASLAN.C WORMS!
    XMicrosoft Synchronization Manageral.exeAdded by the OPTXPRO.132 TROJAN!
    XMicrosoft Synchronization Managerwin.exeAdded by the SDBOT.AK WORM!
    XMicrosoft Synchronization Managerjava.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Synchronization Managersvchosts.exeAdded by the SDBOT-LM WORM!
    XMicrosoft Synchronization Managerwinlogon32.exeAdded by the SDBOT.AEU WORM!
    XMicrosoft Synchronization Managersvxhost.exeAdded by the SDBOT-ZU WORM!
    XMicrosoft Synchronization Managerwincfg32.exeAdded by the SDBOT.DO WORM!
    XMicrosoft Synchronization Managerscreen.exeAdded by the SDBOT-ACO WORM!
    XMicrosoft Synchronization Managerdevldr32.exeAdded by a variant of the RBOT WORM! Note - do not confuse with the legitimate Creative Labs devldr32.exe file
    XMicrosoft Synchronization Managerexplorer.exeAdded by the SDBOT-AEA WORM! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would only be in startups if you added it manually. This one is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    XMicrosoft Synchronization Managerfirewire.exeAdded by the SDBOT-AFC WORM!
    XMicrosoft Synchronization Managerwmedia.exeAdded by the SDBOT.BFC WORM!
    XMicroSoft sys32sysmsgr32.exeAdded by a variant of the SPYBOT WORM! See here
    XMicroSoft sys3s1h4ckn3t.exeDetected by PCTools as the RBOT.QTY WORM! See here
    XMicrosoft Systemmsupdtm.exeAdded by the SPYBOT.PKC WORM!
    XMicrosoft Systemmssys32.exeAdded by the PETTICK.A WORM!
    XMicrosoft Systemsys.exeAdded by the RBOT.AKI WORM!
    XMicrosoft System Backup[random filename]Added by the RBOT-AGM WORM!
    XMicrosoft System CheckupCool.exeAdded by the DONK.B WORM!
    XMicrosoft System CheckupWnetlib.exeAdded by the DONK.C WORM!
    XMicrosoft System Checkupdbnetlib.exeAdded by the DONK.L WORM!
    XMicrosoft System CheckupKeymgr.exeAdded by the DONK.M WORM!
    XMicrosoft System Checkupinetman.exeAdded by the DONK.O WORM!
    XMicrosoft System Checkupntsysmgr.exeAdded by the DONK.S WORM!
    XMicrosoft System Checkupntsysman.exeAdded by the SDBOT-QW WORM!
    XMicrosoft System Checkuplibsysmgr.exeAdded by the SDBOT-CAF WORM!
    XMicrosoft System Checkupsysmgr.exeAdded by the SDBOT-OO TROJAN!
    XMicrosoft System Checkupnetapi32.exeAdded by the DONK-E WORM!
    XMicrosoft System Checkupwnetmgr.exeAdded by the DONK.Q WORM!
    XMicrosoft System Checkuplibsys32.exeAdded by the SDBOT-ACK WORM!
    XMicrosoft System Debugservices32.exeAdded by the RBOT.AKH WORM!
    XMicrosoft System DLL Services Configurationwindir32.exeAdded by the SDBOT-ACY TROJAN!
    XMicrosoft System Filesvchots.exeAdded by the RBOT.BYU WORM!
    XMicrosoft System Firewall 2006.2msmsgr.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft System Firewall 2006.2msnmsgr.exeAdded by a variant of the SDBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility
    XMicrosoft System Firewall 2006.2reg32.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft System Initmtmnr0.exeAdded by the SDBOT.BR TROJAN!
    XMicrosoft System Monitormonsys.exeAdded by the IRCBOT-YV TROJAN!
    XMicrosoft System Monitorsystem.exeDetected by PCTools as the IRCBOT.AUT TROJAN! See here
    XMicrosoft System NTsvhost.exeAdded by the SDBOT.COU WORM!
    XMicrosoft System Restore ConfigurationCBRSS.EXEAdded by a variant of the SPYBOT WORM!
    XMicrosoft System Saver[path to worm]Added by the RBOT.BSK WORM!
    XMicrosoft System Security AgentMSTSA.EXEAdded by the RBOT.CCM WORM!
    XMicrosoft System Servicednservice.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft System Servicetaskmgr1.exeDetected by Kaspersky as the SDBOT.CSX TROJAN! See here
    XMicrosoft System ServicewinIogon2.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft System Service Devicemssdh.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft System Servicesmsnmgsr.exeAdded by the KELVIR.K WORM!
    XMicrosoft System Servicesmsmsgr.exeAdded by the RBOT-ZH WORM!
    XMicrosoft System Updatesysupdate.exeAdded by the SDBOT.DG WORM!
    XMicrosoft system Valuesys57.exeAdded by a variant of the RBOT WORM!
    XMicrosoft System32 Updatecmsrg.exeAdded by the RBOT-GN WORM!
    XMicrosoft task tray monitorctray.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Task32 Protocoltaskmgr32.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Taskmanager Updaterkeyboard.exeAdded by the RBOT-ALU WORM!
    XMicrosoft TCP Protocolwintcp32.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft TCP/IP Connection Monitorsvchost32.exeAdded by the RBOT.KS WORM!
    XMicrosoft Telecom Centertellecom.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Telecoma Centertellcoma.exeAdded by the RBOT-AWX WORM!
    XMicrosoft Telecoms Centertelcoms.exeAdded by the IRCBOT.GEN WORM!
    XMicrosoft Telecoms Centerxpfilesys.exeAdded by the RBOT.BCJ TROJAN!
    XMicrosoft Telecoms Centerwinupn.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Telecoms Centersvcchost.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Time Managerdveldr.exeAdded by the RBOT-HQ WORM!
    XMicroSoft Toolbarkey.exeAdded by the RBOT-AEW WORM!
    XMicrosoft Transfer File Servermtfs.exeAdded by the RBOT.AFE WORM!
    XMicrosoft Tray[random filename]Added by the DELF.BZ TROJAN!
    XMicrosoft TTL Verifiermsttl.exeAdded by the RBOT-GAP WORM!
    XMicrosoft Uwuamkopxp.exeAdded by the RBOT-AHC WORM!
    XMicrosoft UMA UpdateMSuma32.exeAdded by the RBOT.FS WORM!
    XMICROSOFT UNPACCKER SYSTEMunpak32.exeAdded by a variant of the RBOT WORM!
    XMICROSOFT UNPACK SYSTEMwinrarx.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Updat3mswkst32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft UpdateMicrosoft.exeAdded by the GAOBOT.AFJ WORM!
    XMicrosoft Updatemssmgrd.exeAdded by the SDBOT.JT WORM!
    XMicrosoft Updatemvsc.exeAdded by the SPYBOT.DAZ WORM!
    XMicrosoft Updateascdl.exeAdded by the GAOBOT.SY WORM!
    XMicrosoft UpdateIsac.exeAdded by the RBOT-AU WORM!
    XMicrosoft Updateautomgr32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Updatemediap.exeAdded by a variant of the RBOT WORM!
    XMicrosoft UpdateMicrosoftx.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Updatemsconfg.exeAdded by the RBOT.H WORM!
    XMicrosoft UpdateMslti32.exeAdded by the RBOT-LX WORM!
    XMicrosoft Updatemuamgrd.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    XMicrosoft Updatenavmgrd.exeAdded by the SDBOT.DP TROJAN!
    XMicrosoft UpdateSmss32.exeAdded by the RBOT.CB WORM!
    XMicrosoft Updatesys32cfg.exeAdded by the RBOT.DR WORM!
    XMicrosoft UpdateVPC32.EXEAdded by the AGOBOT.XM WORM!
    XMicrosoft Updatewinsys32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Updatewuamgrd.exeAdded by the RBOT-LK WORM!
    XMicrosoft Updatewuammgr32.exeAdded by the RBOT-AW WORM!
    XMicrosoft Updatewudmate.exeAdded by the RBOT.AP WORM!
    XMicrosoft Updatemsawindows.exeAdded by the GAOBOT.AFJ WORM!
    XMicrosoft Updatemsiwin84.exeAdded by the GAOBOT.AFJ WORM!
    XMicrosoft Updatewuamgrd32.exeAdded by the RBOT.ZB WORM!
    XMicrosoft UpdateNAV.exeAdded by the RBOT-IV WORM!
    XMicrosoft Updatesystemi32.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft Updatexpupdate.exeAdded by the RBOT-QE WORM!
    XMicrosoft Updatewebm.exeAdded by the SDBOT.WK WORM!
    XMicrosoft Updatewuagrd.exeAdded by the RBOT-FK WORM!
    XMicrosoft Updateaaupdt.exeAdded by the RBOT-RQ WORM!
    XMicrosoft Updatelsac.exeAdded by the GAOBOT.XW WORM!
    XMicrosoft UpdateMupdate.exeAdded by the RBOT-AG WORM!
    XMicrosoft Updateprowind32.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    XMicrosoft Updatesnlogsvc.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Updatesvhost.exeAdded by the RBOT-PI WORM!
    XMicrosoft Updatewauguard.exeAdded by the RBOT.AEE WORM!
    XMicrosoft Updatewinscv.exeAdded by the RBOT-BH WORM!
    XMicrosoft Updatewinsys.exeAdded by the RBOT-GV WORM!
    XMicrosoft Updatewserv32.exeAdded by the RBOT.AF WORM!
    XMicrosoft Updatewtm32.exeAdded by the RBOT-AQ WORM!
    XMicrosoft Updatewumgrd.exeAdded by the SDBOT-KY WORM!
    XMicrosoft Updatewuampd.exeAdded by the RBOT-UT WORM!
    XMicrosoft Updatemsupdate32.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft UpdateBotnet.exeAdded by the RBOT.AFL WORM!
    XMicrosoft Updatesghost.exeAdded by the SDBOT.AKV WORM!
    XMicrosoft Updateupdate_w.exeAdded by the RBOT-EW WORM!
    XMicrosoft Updatewindows24.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Updatewingrd32.exeAdded by the RBOT-DW WORM!
    XMicrosoft Updatewssvr.exeAdded by the RBOT-OD WORM!
    XMicrosoft Updatewuamagr32.exeAdded by the SPYBOT.CG WORM!
    XMicrosoft UpdateWinUpdate32.exeAdded by the RBOT-TI WORM!
    XMicrosoft Updatewkfix.exeAdded by the RBOT-ABZ WORM!
    XMicrosoft UpdateKkk.exeAdded by the RBOT-AHL WORM!
    XMicrosoft Updatemcupdate.exeAdded by the RBOT.XT WORM! Note - this file is located in the WindowsSystem32 or WinntSystem32 folder, and should not be confused with the McAfee antivirus executable as described here
    XMicrosoft UpdateMicr0s0ft.exeAdded by the AGOBOT.AAR WORM!
    XMicrosoft UpdateMsnmsngr.exeAdded by the RBOT.BQS WORM!
    XMicrosoft Updatemsupdate32.exeAdded by the SPYBOT.LZ WORM!
    XMicrosoft Updatescvhost.exeAdded by the RBOT-AEM WORM!
    XMicrosoft Updatesvghost.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Updatesys.exeAdded by the RBOT-AJ WORM!
    XMicrosoft Updateup2dat5.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Updatewinamp.exeAdded by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player
    XMicrosoft Updatewin-mang.exeAdded by the RBOT-AFK WORM!
    XMicrosoft Updatewinupdater.exeAdded by the RBOT.BIN WORM!
    XMicrosoft Updatewuamk0032.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Updatewuamk032.exeAdded by the RBOT-AHD WORM!
    XMicrosoft Updatewuamk0p32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Updatewuamkop.exeAdded by the RBOT-AFI WORM!
    XMicrosoft Updatewuamkop32.exeAdded by the RBOT.BGU WORM!
    XMicrosoft Updatewuampkd.exeAdded by the SDBOT.BBX WORM!
    XMicrosoft Updatesvzhost.exeAdded by the RBOT.OX WORM!
    XMicrosoft Updatewin32.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Updatewininit.exeAdded by the RBOT-AKR WORM!
    XMicrosoft Updatewuamgrd3.exeAdded by the RBOT-AMC WORM!
    XMicrosoft UpdateWudates.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Updatems.exeAdded by the SDBOT.CC WORM!
    XMicrosoft Updatewuagmsd.exeAdded by the RBOT-AX WORM!
    XMicrosoft Updatecmss.exeAdded by the RBOT-ATQ WORM!
    XMicrosoft Updatewuamgrb.exeAdded by the RBOT-AZE WORM!
    XMicrosoft UpdateWINDOC.EXEAdded by the SDBOT.PF WORM!
    XMicrosoft Updatephqghumea.exeAdded by the SDBOT.AFO WORM!
    XMicrosoft Updatesystem32.exeAdded by the RBOT.IS WORM!
    XMicrosoft Updatebling.exeAdded by the RBOT-AVK WORM!
    XMicrosoft UpdateSygate.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Updateupdate.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft UpdateWinDrv32.exeAdded by the RBOT.EGW WORM!
    XMicrosoft Updatedevmks32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Updatedevmks32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft updatewinupdate.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Updatemsupdate.exeAdded by the BOROBOT-I TROJAN!
    XMicrosoft Updatemixer.exeAdded by the RBOT-AIR WORM!
    XMicrosoft Updatetaskmgr32.exeAdded by the RBOT-CV WORM!
    XMicrosoft Updatedrive.exeAdded by the BIFROSE-PN WORM!
    XMicrosoft Updatewangard.exeAdded by the RBOT-LH WORM!
    XMicrosoft Updatespool.exeAdded by the AGENT-GJC TROJAN!
    XMicrosoft Update 23NtKernelSystem.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Update 23spoolvs.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Update 32explore32.exeAdded by the SPYBOT.CYM WORM!
    XMicrosoft Update 32MSupdate32.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft Update 32wininit.exeAdded by the RBOT-ANY WORM!
    XMicrosoft Update 32wininit32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Update 32[path to file]Added by the RBOT-AJJ WORM!
    XMicrosoft Update 32mscnfg.exeAdded by the RBOT-ALM WORM!
    XMicrosoft Update 32servic.exeAdded by the RBOT-AXN WORM!
    XMicrosoft Update 32winitXP32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Update 32mssetup32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Update 32wiit.exeAdded by the RBOT-AMS WORM!
    XMicrosoft Update 32explorer.exeAdded by the RBOT-ARF WORM! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    XMicrosoft Update 32network.exeAdded by the RBOT-ARZ WORM!
    XMicrosoft Update 32om4r.exeAdded by the RBOT-AQP WORM!
    XMicrosoft Update 32winin.exeAdded by the RBOT-ARR WORM!
    XMicrosoft Update 32wuinit.exeAdded by the AGOBOT-UE WORM!
    XMicrosoft Update 32neta.exeAdded by the RBOT-AMI WORM!
    XMicrosoft Update 33init.exeAdded by the RBOT-ATT WORM!
    XMicrosoft Update 64 BITwininit32.exeAdded by the RBOT-AHE WORM!
    XMicrosoft Update 64 BITwinman32.exeAdded by the RBOT-AKI WORM!
    XMicrosoft Update 64 BITschvost.exeAdded by the RBOT.CAU WORM!
    XMicrosoft Update 64 BITwinl32xe.exeAdded by the RBOT-AQO WORM!
    XMICROSOFT UPDATE CONFIGURATIONWIN32SNC.EXEAdded by the RBOT-AI WORM!
    XMicrosoft Update ControlMs64.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Update Debuggerwincfg32.exeAdded by the SPYBOT.ZC WORM!
    XMicrosoft Update Device Driverswuauclt.exeAdded by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup!
    XMicrosoft Update DLLrxxhost.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Update Driversexplorers.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Update Emulatorkern-mxe.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Update Loader[random filename]Added by a variant of the RBOT WORM!
    XMicrosoft Update Loaders 2005winusers.exeAdded by the RBOT-AIQ WORM!
    XMicrosoft Update Loaders 2006winusersystem32.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    XMicrosoft Update Machineexpl0rer.exeAdded by the SDBOT.OK WORM!
    XMicrosoft Update Machinerxhost.exeAdded by the RBOT.FC WORM!
    XMicrosoft Update Machineservicz.exeAdded by the RBOT-HU WORM!
    XMicrosoft Update MachineSP2.exeAdded by the SPYBOT.FP WORM!
    XMicrosoft Update Machinewinini.exeAdded by the RBOT-KV WORM!
    XMicrosoft Update Machinexvshost.exeAdded by the RBOT.QP WORM!
    XMicrosoft Update Machinememstat.exeAdded by the RBOT-OM WORM!
    XMicrosoft Update Machinentce.exeAdded by the RBOT-FA WORM!
    XMicrosoft Update Machinesystem03.exeAdded by the RBOT-NM WORM!
    XMicrosoft Update Machinewuawx.exeAdded by the RBOT-CE WORM!
    XMicrosoft Update Machinezonealarm.exeAdded by the RBOT-BZ WORM! Note - this is not the valid Zone Labs firewall program!
    XMicrosoft Update Machinesystemll.exeAdded by the RBOT-JT WORM!
    XMicrosoft Update Machinewinupdt.exeAdded by the RBOT-FP WORM!
    XMicrosoft Update Machinesvshost.exeAdded by the RBOT.AK WORM!
    XMicrosoft Update Machinewuamgd.exeAdded by the SDBOT.HQ WORM!
    XMicrosoft Update Machinewupdt32x.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Update Machine[random filename]Added by a variant of the RBOT WORM!
    XMicrosoft Update Machinelinux.exeAdded by the RBOT-IM WORM!
    XMicrosoft Update Machinelmrss.exeAdded by the RBOT-DY WORM!
    XMicrosoft Update Machinewindowsu.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Update Machinewininigo.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Update Machinewinmgr.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Update MachineWinmsixp32.exeAdded by the RBOT.DN WORM!
    XMicrosoft Update MachineWinregs32.exeAdded by the RBOT.DN WORM!
    XMicrosoft Update Machinewinxpini.exeAdded by the RBOT-OB WORM!
    XMicrosoft Update Machinewuamgrd.exeAdded by the RBOT-HE WORM!
    XMicrosoft Update Machinewuagrd.exeAdded by the RBOT-GF WORM!
    XMicrosoft Update MachineLANWAKE.EXEAdded by the RBOT-QZ WORM!
    XMicrosoft Update Machinescvhost.exeAdded by the RBOT-GS WORM!
    XMicrosoft Update Machinewinhost.exeAdded by the RBOT-GK WORM!
    XMicrosoft Update Machinewinss.exeAdded by the RBOT.JU WORM!
    XMicrosoft Update MachineWUAMGRDXS.EXEAdded by the RBOT-GL WORM!
    XMicrosoft Update Machinecrss32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Update Machinelsasse.exeAdded by the RBOT-DI WORM!
    XMicrosoft Update Machineqwerty.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Update Machinerxxhost.exeAdded by the RBOT.EP WORM!
    XMicrosoft Update Machineservicez.exeAdded by the SPYBOT.BI WORM!
    XMicrosoft Update Machinespoolserv.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Update MachineSystemnt.exeAdded by the RBOT.DA WORM!
    XMicrosoft Update Machinesystemse.exeAdded by the RBOT-BD WORM!
    XMicrosoft Update Machinetaskmngrs.exeAdded by the RBOT-CR WORM!
    XMicrosoft Update Machinewindowsup.exeAdded by the RBOT-FV WORM!
    XMicrosoft Update Machinewuamgard.exeAdded by the SPYBOT.CS WORM!
    XMicrosoft Update Machinewupdate32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Update Machinesystem.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Update MachineTMEMSER.EXEAdded by the RBOT-NQ WORM!
    XMicrosoft Update Machinewinnie.exeAdded by the RBOT-ACD WORM!
    XMicrosoft Update Machinewinortho.exeAdded by the RBOT-NW WORM!
    XMicrosoft Update Machinewins32.exeAdded by the RBOT.EZ WORM!
    XMicrosoft Update Machineserviz.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Update MachineTASKMAN4.EXEAdded by a variant of the RBOT WORM!
    XMicrosoft Update Machinewftestb.exeAdded by the RBOT-AFZ WORM!
    XMicrosoft Update MachineWin32.exeAdded by the SDBOT.UV WORM!
    XMicrosoft Update Machinewindns.exeAdded by the RBOT.EF WORM!
    XMicrosoft Update MachineMSOICONS.EXEAdded by the RBOT.AWS WORM! Note - do no confuse with the legitimate Msoicons.exe file described here. The latter should not normally figure in Msconfig/Startup!
    XMicrosoft Update MachineWINSVC32.EXEAdded by the RBOT.CU WORM!
    XMicrosoft Update Machinentsystem.exeAdded by the RBOT.GF WORM!
    XMicrosoft Update Machinewinupdte.exeAdded by the RBOT-GKL WORM!
    XMicrosoft Update Machinejkfrnz.exeAdded by the RBOT-GOZ WORM!
    XMicrosoft Update Machinewlimyc.exeAdded by the RBOT-GQN WORM!
    XMicrosoft Update ManagerWINRLS.EXEAdded by the RBOT-AF WORM!
    XMicrosoft Update Managersvshost.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Update Managerscvhost.exeAdded by the AGOBOT.AXJ WORM!
    XMicrosoft Update Managerscvideo.exeAdded by the SDBOT-CVP TROJAN!
    XMicrosoft Update MecheneUpdatez.exeAdded by the RBOT-GI WORM!
    XMicrosoft Update Modulerundll24.exeAdded by the RBOT-PS WORM!
    XMicrosoft Update Processwmipcvse.exeAdded by the AGOBOT-JF TROJAN!
    XMicrosoft Update Security Patchmssecurityupdatepatch.exeAdded by the AGENT.EF TROJAN!
    XMicrosoft Update Servermssrv.exeAdded by an unidentified VIRUS, WORM or TROJAN!
    XMicrosoft Update Servicecsrss32.exeAdded by the AGOBOT-HC WORM!
    XMicrosoft Update Servicemswin32.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft update servicesystemm.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Update SERVICEphqghum.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Update Servicemsupdate.pifAdded by the RBOT-AQB WORM!
    XMicrosoft Update Serviceswcsnfty.exeAdded by the RBOT-AGK WORM!
    XMicrosoft Update Serviceswsnfty.exeAdded by the RBOT-AFU WORM!
    XMicrosoft Update Timewuam.exeAdded by the RBOT-M WORM!
    XMicrosoft Update USB2wuammgrd32.exeAdded by the RBOT-ADT WORM!
    XMicrosoft Update v2.6lxxex.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Update Win32awinupdate32a.exeAdded by the RBOT-LO WORM!
    XMicrosoft Update Win32xwinupdate32x.exeAdded by the RBOT-AJN WORM!
    XMicrosoft UpdaterWinsys32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Updatermsconsole.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft Updatersvhost.exeDetected by Kaspersky as the AGENT.CDF TROJAN! See here
    XMicrosoft Updatervbcjlg.exeAdded by a variant of the SPYBOT WORM! See here
    XMicrosoft Updaterwuamgrds.exeAdded by the RBOT.A WORM!
    XMicrosoft Updater ResourcesWinFixd32.exeAdded by the SPYBOT.CA WORM!
    XMicrosoft UPDATER32lsass.exeAdded by the RANDEX.AR WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!
    XMicrosoft Updaterstskmgr.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Updaterssysconfigs.exeAdded by the RBOT-DF TROJAN!
    XMicrosoft Updaters ProsWINDLL32XP.EXEAdded by the SPYBOTTER.GEN VIRUS!
    XMicrosoft Updatessystemc32.exeAdded by the RBOT-GR WORM!
    XMicrosoft Updateswkssvr.exeAdded by the RBOT.R WORM!
    XMicrosoft Updateswkssvrs.exeAdded by the RBOT-EB WORM!
    XMicrosoft Updateswuamgrd.exeAdded by the RBOT-CO WORM!
    XMicrosoft Updateswtemp32.exeAdded by the RBOT-AHQ WORM!
    XMicrosoft Updatessvehost.exeAdded by the RBOT-GRW WORM!
    XMicrosoft Updatessvshost.exeAdded by the AGOBOT-AIW WORM!
    XMicrosoft Updatessvdhost.exeAdded by the RBOT-GVH WORM!
    XMicrosoft Updates 2 USBwgafixer.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Updates 5 USBsp3fixer.exeAdded by the RBOT-ADS WORM!
    XMicrosoft Updates ResourcesWinFixIDs.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Updatingnavguard.exeAdded by the RBOT.HW WORM!
    XMicrosoft Updatingsyswr.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Updatingwuamguards.exeAdded by the RBOT-BY WORM!
    XMicrosoft Updating Clientwebsvc.exeAdded by the RBOT.AQ WORM!
    XMicrosoft Updating Machinesysc0de.exeAdded by the RBOT.RB WORM!
    XMicrosoft Updattingmiroupdate.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Updote[random filename]Added by the RBOT-ARC WORM!
    XMicrosoft UpMachinedoezs.exeAdded by the RBOT.BCT WORM!
    XMicrosoft upnp Updatemsie.exeAdded by the RBOT-LQ WORM!
    XMicrosoft uptime Servicesysuptime.exeAdded by the RBOT-ACG WORM!
    XMicrosoft uptime Servicesycuptime.exeAdded by the RBOT-AHY WORM!
    XMicrosoft UpToDate Driver (32-bits)[random filename].exeAdded by the SPYBOT.LXJ WORM!
    XMicrosoft Urlmonurlmon.exeAdded by the AGENT-GOO TROJAN!
    XMicrosoft USB2 Drivercrmss.exeAdded by the RBOT-VK WORM!
    XMicrosoft usnsvc Serviceusnsvc.exeAdded by a variant of the KOBOT-C WORM!
    NMicrosoft Utility StartupOSA9.exeApplication which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
    XMicrosoft Valuesigfkishc.exeAdded by the RBOT-GLO WORM!
    XMicrosoft VertupdateMSvert32.exeAdded by the MYTOB-CY WORM!
    XMicrosoft Video Capture ControlsMSsrvs32.exeAdded by the SDBOT-AAK WORM!
    XMicrosoft Video Controlstskmsgr.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft Viewer Monitor Managerviewmon.exeDetected by Trend Micro as the XPAK.A TROJAN! See here
    XMicrosoft Virtual Service Managervservice32.exeDetected by Trend Micro as the MSNWORM.T WORM! See here
    XMicrosoft Virual Machinesms.exeAdded by the RBOT-SP WORM!
    XMicrosoft Visual Applicationvpcrtf.exeAdded by the IRCBOT-XJ TROJAN!
    XMicrosoft Visual SourceSafeservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
    XMicrosoft Visual SourceSafewinlogon.exeAdded by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
    XMicroSoft Visual SP2igfxsrvc32.exeDetected by Trend Micro as the SDBOT.GAV WORM! See here
    XMicrosoft Visual Studioplscdksxg.exeAdded by the RBOT-AWV WORM!
    XMicrosoft Visual Studio VSAvarpc32.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft Web CP Managerwebcp32.exeAdded by a variant of the SDBOT WORM! See here
    XMicrosoft Web Devicewdevice.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft web updatewebmsn.exeAdded by the RBOT-EMQ WORM!
    UMicrosoft Webserversvctrl.exePersonal web server program which enables you to create and host a web server from your computer. Not required for most people
    XMicrosoft Win Corp TLS Verificationmswintls.exeAdded by the RBOT-GCT WORM!
    XMicrosoft WIN32 DOSMSdos32.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft WIN32 SecurityMSsec32.exeAdded by the RBOT-DOQ TROJAN!
    XMicroSoft Wind0ws Updaterwinsupdater.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Windowsmstask0.exeAdded by the SDBOT.FQ WORM!
    XMicrosoft WindowsatupAdded by a variant of the RBOT WORM!
    XMicrosoft WindowsMicrosoft Windows.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
    XMicrosoft Windowsexplorar.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Windows[path to file]Added by the LI TROJAN!
    XMicrosoft Windowsbootini.exeAdded by the VANEBOT-K WORM!
    XMicrosoft WindowsKernel.exeAdded by the EDIBARA-A VIRUS!
    XMicrosoft WindowsKernel.vbsAdded by the EDIBARA-A VIRUS!
    XMicrosoft Windowspwjbvphi.exeAdded by the RBOT-GQK WORM!
    XMicrosoft Windows 128bit Subsystemsystem12.exeAdded by the RANCK-CZ TROJAN!
    XMicrosoft Windows 16Bitmswinn16.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft Windows 2000Winupdsdgm.exeAdded by the GAOBOT.AO WORM!
    XMicrosoft Windows 32 Updatewin32update.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft Windows 32Bitmswinn32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Windows 64 Bitmswin32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Windows Adapter 5.1.3214[worm filename].exeDetected by Trend Micro as the STRAT.GEN-3 WORM! See here
    XMicrosoft Windows Client Firewallmsclt.exeAdded by the VANEBOT-F WORM!
    XMicrosoft Windows Communicator for NT/XPwincomm.exeAdded by the RBOT.ATH WORM!
    XMicrosoft Windows Config 32win32conf.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Windows Controlmswctl32.exeAdded by the RBOT.JP WORM!
    XMicrosoft Windows CSRSScsrss.exeAdded by the KALEL-A WORM! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
    XMicrosoft Windows DHCP___r.exeAdded by the MASLAN.A or MASLAN.C WORMS!
    XMicrosoft Windows DLL 32-BITmsncheck32.exeAdded by the SDBOT-XX WORM!
    XMicrosoft Windows DLL Servicesmwindll.exeAdded by the SDBOT-VX WORM!
    XMicrosoft Windows DLL Services Configurationnewdll.exeAdded by the SDBOT-ZR WORM!
    XMicrosoft Windows DLL Services Configurationnewdll2.exeAdded by the SDBOT-ABD WORM!
    XMicrosoft Windows DLL Services Configurationpoker.exeAdded by the SDBOT-ZY WORM!
    XMicrosoft Windows DLL Services Configurationpoker3.exeAdded by the SDBOT-AAH WORM!
    XMicrosoft Windows DLL Services Configurationproxy.exeAdded by the SDBOT-ZL WORM!
    XMicrosoft Windows DLL Services Configurationwindir32.exeAdded by the SDBOT.BHF WORM!
    XMicrosoft Windows DLL Services Configurationwindir32a.exeAdded by a variant of the SDBOT.BHF WORM!
    XMicrosoft Windows DLL Services Configurationwindll32.exeAdded by the SDBOT.BHD WORM!
    XMicrosoft Windows DLL Services ConfigurationwinDSL.exeAdded by the SDBOT-ZG WORM!
    XMicrosoft Windows DLL Services Configurationdllmanager32.exeAdded by the SDBOT-BTU WORM!
    XMicrosoft Windows DLLHandlerbitpaint.exeAdded by the SDBOT.AHG WORM!
    XMicrosoft Windows Driverswindrv.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Windows DVRwindvr.exeAdded by the RBOT-AXD WORM!
    XMicrosoft Windows Exploreriexplorer.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Windows Explorerexplorewin.exeAdded by the IRCBOT.WORM.212480.H WORM!
    XMicrosoft Windows Files Loadercgy32win.exeAdded by the RBOT-AXR WORM!
    XMicrosoft Windows Game Updatermsgame32.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Windows GUIWindowz.exeAdded by the RANDEX.AEV WORM!
    XMicrosoft Windows GUImsmonk32.exeAdded by the SDBOT-PE WORM!
    XMicrosoft Windows Kernel Serviceswinkrnl386.exeAdded by the ZEBROXY TROJAN!
    XMicrosoft Windows Loaderwloader.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    XMicrosoft Windows Logon Processwinlogon.exeAdded by the PROXYSER-R TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This worm file is placed in the Winnt or Windows folder
    XMicrosoft Windows Media Playermediaplayer.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Windows Media Playerwimp.exeAdded by the RBOT-FN WORM!
    XMicrosoft Windows Registry Servicewregistry.exeAdded by the AGOBOT.AKG WORM!
    XMicrosoft Windows Securewindocs.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Windows Securewindocs.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Windows Secure ServerrpcxWindows.exeAdded by the RBOT-LL WORM!
    XMicrosoft Windows Secure Updaterpcxwinupdt.exeAdded by an unidentified WORM or TROJAN!
    XMicrosoft Windows Securetywurguar.exeAdded by the RBOT-KY WORM!
    XMicrosoft Windows Securityspvsper.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Windows Securitywscndrives.exeAdded by the RBOT-AJK WORM!
    XMicrosoft Windows Servicewinsys.exeAdded by the RBOT-ADP WORM!
    XMicrosoft Windows Service Packwinspkn.exeAdded by the RBOT-AYD WORM!
    XMicrosoft Windows Servicesmsw32.exeAdded by the RBOT-FWQ WORM!
    XMicrosoft Windows Services Edtssvvcchhoosst.exeAdded by the RBOT-FYF TROJAN!
    XMicrosoft Windows Services Edtdllrun32.exeAdded by the RBOT-GAF WORM!
    XMicrosoft Windows Session Manager Subsystemsmss.exeAdded by the PROXYSER-R TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
    XMicrosoft Windows Socketx32 Serviceswinsockx32.exeAdded by the RBOT-FWT WORM!
    XMicrosoft Windows Storage Machine Servicewinms.exeAdded by the RBOT-AHK WORM!
    XMicrosoft Windows Systemsrwhost.exeAdded by a variant of the RBOT-ASW WORM!
    XMicrosoft Windows Systemsyshost.exeAdded by the RBOT-ASW WORM!
    XMicrosoft Windows System Kernelkernel32.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft Windows System Service Managerwinsvc.exeAdded by the SPYBOT.LR WORM!
    XMicrosoft Windows Task Managementmstasks.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Windows Task MangerMstosk.exeAdded by the SDBOT-WW WORM!
    XMicrosoft Windows Tasks Managementtaskmng.exeAdded by the RBOT-FXK WORM!
    XMicrosoft Windows Updatascvhost.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Windows Updatawindows.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Windows Updaterundlls.exeAdded by the HABRACK WORM!
    XMicrosoft Windows Updatemsoffice2.exeAdded by the RBOT-GB WORM!
    XMicrosoft Windows Updatespools.exeAdded by the SDBOT.TD WORM!
    XMicrosoft Windows Updatesvchos.exeAdded by the SDBOT.AC WORM!
    XMicrosoft Windows Updatesvcshost.exeAdded by the FORBOT-CF WORM!
    XMicrosoft Windows Updatesvmhost.exeAdded by the FORBOT-CH WORM!
    XMicrosoft Windows Updatesvshost.exeAdded by the WOOTBOT.CJ WORM!
    XMicrosoft Windows Updatemsnmessenger.exeAdded by the SDBOT.AJ WORM!
    XMicrosoft Windows Updatemsnwun.exeAdded by the SDBOT-RM WORM!
    XMicrosoft Windows Updatescvvhost.exeAdded by the FORBOT-DH WORM!
    XMicrosoft Windows Updateswwhost.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Windows UpdateMSNMSGR.EXEAdded by the SDBOT-WM WORM!
    XMicrosoft Windows Updatesvzhost.exeAdded by the FORBOT-EV WORM!
    XMicrosoft Windows Updatesccvhost.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Windows Updatescrhost.exeAdded by the RBOT-AOW WORM!
    XMicrosoft Windows Updatemnswinsx.exeAdded by the RBOT-AWH WORM!
    XMICROSOFT Windows updatepdate.exeAdded by the RBOT.BZT WORM!
    XMicrosoft Windows Updatesrshost.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Windows Updaterhost32.exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft Windows Updatewindowsupdate.exeAdded by the AGOBOT.ON WORM!
    XMicrosoft Windows Update Applicationwuap.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Windows Update Clientcsrss.exeAdded by the KEBEDE-G WORM! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
    XMicrosoft Windows Update Logonwin-logon.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Windows Update Servicewupdmgr32.exeAdded by the DOS.AUTOCAT TROJAN!
    XMicrosoft Windows Update x86[various filenames]Added by a variant of the RBOT WORM! Filenames seen include (but are not limited to firefox.exe, opera.exe, taskmrg.exe, aim.exe, Winxdiag.exe and usnesvc.exe
    XMicrosoft Windows Update XP64********.exe [* = random char]Added by a variant of the RBOT WORM!
    XMicrosoft Windows Updaterwinupdgm.exeAdded by the GAOBOT.BI WORM!
    XMicrosoft Windows UpdaterWINIUPDATES.EXEAdded by the RBOT-KK WORM!
    XMicrosoft Windows UpdaterWINUPDATE.EXEAdded by the SDBOT-PU WORM!
    XMicrosoft Windows UpdaterTMNTSrv.exeAdded by a variant of the RBOT WORM!
    XMicrosoft Windows Updaterwin32upd.exeAdded by the RBOT-EC WORM!
    XMicrosoft Windows Updatermsnupdateit.exeAdded by the AGOBOT-RL WORM!
    XMicrosoft Windows Updaterwindates.exeAdded by the SDBOT.TE WORM!
    XMicrosoft Windows Updaterspoolvs.exeAdded by the RBOT.ACQ WORM!
    XMicrosoft Windows Updatersuvhost.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Windows updaterDlog32zx.exeAdded by the MYDOOM.W WORM!
    XMicrosoft Windows Updatesexplorer32.exeAdded by the SDBOT.VQ WORM!
    XMicrosoft Windows Updateswsap32.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft Windows Updating Systemmsresource.exeAdded by the RBOT-EAM WORM!
    XMicrosoft Windows Visual V2.0msiutil.exeAdded by the DELF.JPH TROJAN!
    XMicrosoft Windows W32 Servicesmssw32.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft Windows WinSaSS Managementwinsass.exeAdded by the RBOT-APW WORM!
    XMicrosoft Windows WKS Service gt.exeAdded by the SDBOT.IR WORM!
    XMicrosoft Windows WKS Servicemstask0.exeAdded by the SDBOT.FV WORM!
    XMicrosoft Windows Workstationdevcode.exeAdded by the RBOT-AWL WORM!
    XMicrosoft Windows XP Configuration Loaderm32svco.exeAdded by the SDBOT.WORM!.48548 WORM!
    XMicrosoft Windows XP/2K Explorerwinexplorer.exeAdded by a variant of the IRCBOT TROJAN! See here
    XMicrosoft Winedows WinServiPodFix.exeAdded by a variant of the RBOT WORM!
    XMicrosoft WINGS32 ProtocolWinSGR32.exeAdded by the RBOT-APU WORM!
    XMicrosoft WinRaRwinrar.exeAdded by the RBOT-AEC WORM!
    XMicrosoft Winsockmswinsck.exeAdded by the RBOT-ANK WORM!
    XMicrosoft Winsock Servicemsusvc.exeAdded by the RBOT-ANS WORM!
    XMicrosoft Winsock Wrapperws2_32s.exeAdded by a variant of the SPYBOT WORM!
    XMicrosoft WinSound[random filename]Added by a variant of the RBOT WORM!
    XMicrosoft WinUpdatemntcgf032.exeAdded by the RBOT-PF WORM!
    XMicrosoft WinUpdatesvh0st.exeAdded by the SPYBOT.DL WORM!
    XMicrosoft WinUpdatesyslx32.exeAdded by an unidentified VIRUS, WORM or TROJAN!
    XMicrosoft WinUpdatesyswin32.exeAdded by the RBOT-HO WORM!
    XMicrosoft WinUpdatespfix.exeAdded by a variant of the RBOT WORM!
    XMicrosoft WinUpdateWinamp61.exeAdded by a variant of the RBOT WORM!
    XMicrosoft WinUpdateWinupd32.exeAdded by the RBOT.MQ WORM!
    XMicrosoft WinUpdateWinNTinit32.exeAdded by the RBOT.VS WORM!
    XMicrosoft WinUpdatesserm32.exeAdded by the RBOT.GE WORM!
    XMicrosoft WMmswm32.exeAdded by the BCKDR-AM TROJAN!
    XMicrosoft WordBootSector.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    XMicrosoft Word Profissionalcsrss.exeAdded by the BANCBAN-DB TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "s1613" subfolder
    XMicrosoft Word ProfissionalJava Plug In close.exeAdded by the BANKER-EL TROJAN!
    XMicrosoft Word Profissionalcsrss.exeAdded by the BANKER-DJ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "protect" subfolder
    XMicrosoft Word Profissionalcsrss.exeAdded by the BANKER-DJ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "JavaVM" subfolder
    NMicrosoft Works Calendar Reminderswkcalrem.exeProduces a pop-up reminder of events scheduled using the MS Works Calendar
    NMicrosoft Works PortfolioWksSb.exeThe Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program.Can be prevented from starting from a setting within Portfolio
    NMicrosoft Works Update Detection wkdetect.exeChecks for updates to MS Works
    XMicrosoft World Servicewinworld.exeAdded by an unidentified IRC worm with backdoor capability!
    XMicrosoft WPCEmailsvchost.exeAdded by the SNIFFER-N TROJAN!
    XMicrosoft WWWfree.exeAdded by a variant of the CWS.AK TROJAN!
    XMicrosoft WxdateSyswu32.exeAdded by the SPYBOT.HZ WORM!
    XMicrosoft X Updatewuamkoppnp.exeAdded by the RBOT-ANI WORM!
    Xmicrosoft xdaemon 2.0xdaemon.exeAdded by the DELF.D TROJAN!
    XMicrosoft XML Servicemsxmlx.exeAdded by the RBOT.KS WORM!
    XMicrosoft Xp Systems loaderwinsystem32xp.exeAdded by the KELVIR.W WORM!
    XMicrosoft Xp Systems loaderswin32xpsys.exeAdded by the SPYBOT.NYT WORM!
    XMicrosoft XPSP Protocolxp386.exeAdded by a variant of the RBOT WORM!
    XMicrosoft xpsp2Networksystem.exeAdded by a variant of the SDBOT WORM!
    XMicrosoft xpsp2xpsp2.exeAdded by the SDBOT-YQ WORM!
    XMicrosoft's System ModuleSysmodule.exeAdded by the FJ TROJAN!
    XMicrosoft--Updatessxvhost.exeAdded by the RBOT-FH WORM!
    XMicrosoft-software****.exe [* = random char]Added by a variant of the RBOT WORM!
    XMicrosoft-Updatewngard.exeAdded by the RBOT-JV WORM!
    XMicrosoft-Updatessvxhost.exeAdded by the RBOT-CT WORM!
    XMicrosoft.exe[random].exeAdded by a variant of the IRCBOT TROJAN!
    XMicrosoft32win32sys.exeAdded by an unidentified WORM or TROJAN!
    Xmicrosoft420microsoft420.exeAdded by the MENACE.B WORM!
    XMicrosoft64antiv.exeAdded by the SOBER WORM!
    XMicrosoft? ActiveX Debugger NTsetdebugnt.exeAdded by the BANCOS-CZ TROJAN!
    XMicrosoft? PID LexPIDLex.exeAdded by the NIOVADOOR TROJAN!
    XMicrosoft? System MapperSysMap.exeAdded by the MAPSY TROJAN!
    UMicrosoft? Windows? Operating SystemehTray.exeMicrosoft Media Center Tray Icon gives easy access to the digital media manager for Windows Vista Home Premium and Media Center Edition
    NMicrosoft? Windows? Operating SystemRunDLL32.exe ehuihlp.dll, BootMediaCenterStarts Windows Media Center every time Windows Vista (Home Premium or Ultimate) boots. Disable by unchecking the "Start Windows Media Center when Windows Starts" option via Windows Media Center -> Tasks -> Settings -> General -> Startup and Window Behaviour
    NMicrosoft? Windows? Operating Systemrundll32.exe oobefldr.dll, ShowWelcomeCenterShows the Welcome Center every time you boot into Windows Vista
    XMicrosoftDriverService32drsys32.exeDetected by Trend Micro as the IRCBOT.AKX TROJAN! See here
    XMicrosoftf DDEs ContDLLrune.pifAdded by the RBOT-AGF WORM!
    XMicrosoftf DDEs ContrDLrunm.pifAdded by the RBOT-AFQ WORM!
    XMicrosoftf DDEs Controllxes.exeAdded by the RBOT.BOF WORM!
    XMicrosoftf DDEs Controlwees.exeAdded by a variant of the RBOT WORM!
    XMicrosoftf DDEs Controlsoff.pifAdded by the RBOT-AKH WORM!
    XMicrosoftf DDEs Controlwhy-.exeAdded by the RBOT-AMV WORM!
    XMicrosoftf DDEs Controlmsnn.exeAdded by the RBOT-AXT WORM!
    XMicrosoftf DDEs ControlFEnR.exeAdded by the RBOT-AIM WORM!
    XMicrosoftf DDEs Controlw33s.exeAdded by a variant of the RBOT WORM!
    XMicrosoftf DDEs Controlwaes.exeAdded by a variant of the RBOT WORM!
    XMicrosoftkeysdsystemproc.exeAdded by the FORBOT-BI WORM!
    XMicrosoftkeysdsystemwin32s.exeAdded by the WOOTBOT.CO WORM!
    XMicrosoftkeysdslass32.exeAdded by a variant of the RBOT WORM!
    XMicrosoftKsDrivers.batAdded by the SHUTDOWN-F TROJAN!
    Xmicrosoftm eegs cuntrolloor.pifAdded by a variant of the RBOT WORM!
    XMicrosoftMessengermsnserv.exeAdded by the DARKER.M WORM!
    XMicrosoftmsn32.exemicrosoftmsn32.exeAdded by the CERTIF-C TROJAN!
    XMicrosoftMultimediaTaskMmtask.exeAdware downloader - not the valid MusicMatch Jukebox which shares the same filename
    XMicrosoftNetwork Daemon for Win32NETD32.EXEAdded by the RANDEX.F WORM!
    XMicrosoftOEMsmvss.exeAdded by the DEDLER-G TROJAN!
    XMicrosoftROMDriverServicecdrss.exeDetected by Kaspersky as the IRCBOT.BLF TROJAN! See here
    XMicrosofts mediawinmplayd.exeAdded by an undidentified WORM or TROJAN!
    XMicrosofts mediawingtp.exeAdded by the RBOT-VO WORM!
    XMicrosofts MediaScopewinmep.exeAdded by the RBOT-WB WORM!
    XMicrosofts MediaScopewinmedplay.exeAdded by a variant of the RBOT WORM!
    XMicrosofts Security Manager****.exe [**** = random char]Added by the RBOT-WH TROJAN!
    XMicrosofts Servicelcsrv16.exeAdded by a variant of the RBOT WORM!
    XMicrosofts Updateslsasss.exeAdded by the RBOT-AEX WORM!
    XMicrosofts Updatezcmsssr.exeAdded by an unidentified VIRUS, WORM or TROJAN!
    XMicrosofts Updatezexploirez.exeAdded by a variant of the RBOT WORM!
    XMicrosoftServiceManagermstask32.exeAdded by the YAHA.P WORM!
    XMicrosoftServiceManagerWintsk32.exeAdded by the YAHA.U WORM!
    XMicrosoftServiceManagerEXPLORERE.EXEAdded by the YAHA.AB WORM!
    XMicrosoftServiceManagermsupdat.exeAdded by the YAHA.AA WORM!
    XMicrosoftShellShellcomm.exeAdded by the BANCBAN-QG TROJAN!
    XMicrosoftSourceSafelsass.exeAdded by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder
    XMicrosoftSysSPOOLSYS.exeAdded by the TARNO.N TROJAN!
    XMicrosoftUpdatesyshelper.exeAdded by the WOOTBOT.AC WORM!
    XMicrosoftUpdateWinUp32.exeAdded by an unidentified VIRUS, WORM or TROJAN!
    XMicrosoftUpdateMicrosoftUpdate.exeAdded by the BANKER-EHC TROJAN!
    XMicrosoftUpdatewindll.exeAdded by the RBOT-IH WORM!
    XMicrosoftUpdates[path to trojan]Added by the DELF-LO TROJAN!
    XMicrosoftValuesyscnfg.exeAdded by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside
    XMicrosoftvirussysoverload.exeAdded by the FORBOT-AL WORM!
    XMicrosoftWindows[various filenames]MagicSearch - a CoolWebSearch parasite variant
    XMicrosoftWindowsa@26m.exeAdded by the KILLPAR-B TROJAN!
    XMicrosoftXP Service Pack 2servicepack2.exeAdded by the RBOT.EMC WORM!
    XMicrosoftz turn Controlaexl.exeAdded by the SDBOT.BCO WORM!
    XMicrosoftz turn Controlread.pifAdded by the RBOT-AFS WORM!
    XMicrosongsvchosts11.exeAdded by the SDBOT-EV WORM!
    XMicrosot NT Support[random filename].exeAdded by the RBOT-CTI WORM!
    Xmicrosystemsnddrv.exeDetected by Kaspersky as the VB.AXG TROJAN!
    XMicroszoft Update Mach1nezssvchst.exeAdded by the RBOT-ED WORM!
    UMicrotek Scanner FinderScannerFinder.exeMonitors whether a scanner is present. Provided with Microtek scanners
    XMicrozoft_OfizKdzEregli.exeAdded by the AMUS.A WORM!
    XMicrsoft CFG 32lrbzus32.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    XMicrsoft DerSystemuqieelpb.exeAdded by the RBOT-GRI WORM!
    XMicrsoft Driverwindrive.exeAdded by the SDBOT.AF TROJAN!
    XMicrsoft Drivermsdriver.exeAdded by the SDBOT-XD WORM!
    XMicrsoft Internet ExplorerIEXPL0RE.EXEAdded by the RBOT-AQV WORM! Note the number "0" in the filename
    XMicsoft-Published-Softwareexplrer.exeAdded by the RBOT-GFL WORM!
    XMicsorosft Security Centerwcnsfty.exeAdded by the RBOT-AHU WORM!
    NMightyFAX ControllerMFNTCTL.EXEMighty FAX from RKS Software - "installs a printer driver so that you can fax directly from Windows software"
    ?MigrationVendorSetupCallerrundll32.exe migrate.dll, CallVendorSetupDlls??
    XMilitary Net KillerMNK.exeAdded by the MILLNET-A WORM!
    UMilShieldSlaveShieldWorker.exeMil Shield from Mil Incorporated. It protects your privacy by removing all tracks from your online or offline computer activities
    NMimBootmimboot.exeStarts Musicmatch Jukebox at bootup - can be started manually
    XMincerMincer.exeAdded by the MINCEME-A WORM!
    UMindfulMindful.exeMindful from Felitec inc. "Event reminder software with date and time tools in a simple to use system tray application"
    XMINIBUGMINIBUG.EXEDisplays ads inside Weatherbug - see here
    NMiniEYE-MiniREAD LaunchARLaunch.exeeyeQ - improve your reading speed
    NMINIFERT.EXEMINIFERT.EXEPart of Backweb
    UminilogMINILOG.EXEIf you don't have ZoneAlarm or ZoneAlarm Pro running you don't need this. This must be enabled if programs such as VisualZone Report utility or ZoneLog Analyzer are in use
    NMiniMavisMiniMavis.exeMavis Beacon typing tutor
    Xminimo[path to file]Added by the MOSUCK-X TROJAN!
    NMiniNoteMININOTE.EXEMini NoteTab was the first in the family of "NoteTab" text and HTML editors from Fookes Software
    ?Miniphoneglophone.exeVoiceGlo Glophone Voice over Internet Protocol (VOIP) communications software - "an affordable and convenient way to call friends and family throughout the world using a dial-up or broadband Internet connection on your computer" - is it required in startup?
    Xminiportusb2chk.exeAdded by the LAZAR-A TROJAN!
    XMiniPortRtminiport_mp.exeMalware - see here
    UMiniReminderMiniReminder.exe"MiniReminder is a small, fast, and simple program for Microsoft Windows to remind yourself of important yearly events, like birthdays, anniversaries, renewals, etc"
    XMiniServer.exeMiniServer.exeAdded by the LITTLEW-E TROJAN!
    UMinMaxExtenderMmext.exeMinMaxExtender - window handling tool
    XMioft Wiws Seice ent[worm filename].exeAdded by the RBOT-GIJ WORM!
    XMiosf Updatewimsqaad.exeAdded by the SDBOT.AG TROJAN!
    UMioSyncmioSync.exeRelated to Mio GPS navigation devices
    NMirabilis ICQNDetect.exeIf connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs
    NMirabilis ICQicq.exeIf connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs
    NMirabilis ICQICQNet.exeIf connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs
    UMiramar Systems, Inc.atmsg.exeMiramar PC/Mac networking software
    NMiranda IMmiranda32.exeMiranda instant messaging client
    XMirate Sp 2 Informationmiratesp2.exeAdded by the RBOT.QH WORM!
    XMircosoft DNS Servicesvchost.exeAdded by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "drivers" subfolder
    XMircosoft Sockets SP2mssck.exeAdded by the MYTOB.ET WORM!
    XMircosoft Updatewuampkd.exeAdded by a variant of the SDBOT WORM!
    XMircrosoft Svchost32svchost32.exeAdded by the RBOT-AZW WORM!
    XMircrosoft Windows Config DLLrundllc32b.exeAdded by the RBOT-ZY WORM!
    NmiroVIDEO Tray Toolmisitray.exeTool for quickly changing options for miro/Pinnacle capture cards during capture/playback/output. When this program is closed, another program (mv-ctrl) is also closed, but mv-ctrl does not have its own EXE file. Only needed when using the capture card, e.g. for the above actions
    UMirraMirra.Client.exeMirra Personal Server from Seagate Tech - "a powerful hardware/software solution that integrates high-capacity storage with content protection, remote access, sharing and multi-computer synchronization"
    UMirrorFolderShellmrfshl.exeMirrorFolder backup software
    XMirsoft sdcEtaskmegr.exeAdded by the RBOT-AWY WORM!
    XMirsoft sdcEtaskmegr.exeAdded by the RBOT.DFQ WORM!
    XMiscrosoft Windows ExplorerIEEXPLORER.exeReported as the SDBOT.YX WORM!
    ?misiCTRLmisiCTRL.exeMiro video driver related. Is it required?
    ?misiTRAYmisiTRAY.exeMiro video driver related. Is it required?
    XMismowin32x.exeAdded by the RBOT-JP WORM!
    NMixerMixer.exeC-Media Mixer - C-Media produce audio chipsets that are often found on popular motherboards with on-board audio. Provides System Tray access to change audio settings. Available via Start -> Settings -> Control Panel or Start -> Programs
    NMixerselmixersel.exeConfiguration for Realtek audio devices
    NMixghostmixghost.exeManagement software for Altec Lansing speakers.  If a change is needed, the user can launch it from the Start menu
    XMJte32.exeAdded by the AGENT.HAA TROJAN
    Xml00!.exeml00!.exeMalware, detected by Panda Antivirus as Trj/Downloader.BWD
    UML1HelperStartUpML1HEL~1.EXEScreenScenes "Midnight Lake" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here
    UML1HelperStartUpML1Helper.exeScreenScenes "Midnight Lake" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here
    Xml34[path to trojan]Added by the MAILBOT-BH TROJAN!
    XMlcr0s0ftf DDEs C0ntr0iWAed.pifAdded by the RBOT-BJW WORM!
    Xmlibsysmccomzcinc.exeAdded by the SDBOT-CXS WORM!
    Xmloadlxmstart.exeAdded by an unidentified VIRUS, WORM or TROJAN!
    ?MM Installsetup.exePossibly Money Manager from Moneysoft?
    XMMB2explorer.exeAdded by an unidentified WORM or TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    XMMCinisys.exeAdded by the OSCABOT-I WORM!
    Xmmcndmgrmmcndmgr.exeAdded by an unidentified VIRUS, WORM or TROJAN!
    NMMCWINMGMTwinmgmt.exeUsed for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer here
    Xmmemdrvmmemdrv.exeSecondSight spyware. Note - SecondSight is spyware that captures keystrokes and screen shots, and logs user activity on the compromised computer. The risk can then send the logged information to a remote attacker via email, must be manually installed
    UMMERefreshMMERefresh.exePart of Digidesgin Protools. Refreshes your midi ports on the 002(R) (the 002R is a hardware audio/midi converter connected to your computer via firewire). Must be running in order to use the MIDI functionality of the Digi002R
    XMmessengermessenger.exeAdded by the AGOBOT.GM WORM!
    XMmgsvcmmgsvc.exeMmgsvc spyware
    UMMhidmmhid.dllThis is the Human Interface Device Server for Win98, it is required only if you are using USB Audio Devices you can disable via Msconfig. See here. Typical examples are USB multimedia keyboards with volume control and web-ready keyboards. For example - loaded by default with MS DSS80 Speakers because they have Volume, Mute and Bass controls on the speaker. Some users may experience problems disabling this - if this is the case then re-enable it. Equivalent to Hidserv in Win98SE/2000/Me/XP
    ?MMHKmmhk.exeA driver found on a Compaq Presario 800T notebook. Possibly something to do with multimedia hot keys?
    NMMHotKeyMMHotKey.exeMultimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen
    XMMicrosoft Security Managementinetforn.exeAdded by the RBOT.AFZ WORM!
    UMMKeybdMMKeybd.exeMultimedia keyboard manager. Required if you use the additional keys
    UMmmMmm.exeHace Mmm - free utility to configure your Windows menus and move and remove menu-items you never use
    Xmmodmmod.exeeZula TopText adware
    Nmmptim1mmpti.exeMpact Mediaware Properties Taskbar Icon - multimedia software icon for Chromatic Research Mpact video cards
    NMMReminderServiceMMReminderService.exeMind Manager from Mindjet - "easy way to organize ideas and information". Registration reminder
    ?MMRunmmrun.exe??
    Xmmsassmmdmm.exeAdded by a variant of the SDBOT WORM! See here
    Xmmsddlx[random filename]Added by a variant of the SLAPER TROJAN!
    ?mmsysrecover.exe??
    XMMSystemRunDll32Added by the FUNNER-A WORM!
    YMMTASKmmtask.tskA check on the file's properties reveals "Multimedia background task support module". MMTASK is a very simple 16-bit program used by certain multimedia drivers (which are still 16-bit on Win9x) to perform background processing. Some soundcards need this to support MIDI, etc
    Nmmtaskmmtask.exePart of MusicMatch Jukebox - digital music player / CD burner and ripper / music organizer / playlist creator
    XMMtask Servicemmtask.exeAdded by the BACKGAT.A TROJAN! Not the valid MusicMatch Jukebox which has the same filename
    NMMTraymm_tray.exeMusicMatch Jukebox icon in the task tray - digital music player / CD burner and ripper / music organizer / playlist creator
    NMMTrayMMTray.exePart of Morgan Multimedia Codecs. Only required when the codecs are used
    NMMTray2KMMTray2K.exePart of Morgan Multimedia Codecs. Only required when the codecs are used
    NMMTrayLSIMMTrayLSI.exePart of Morgan Multimedia Codecs. Only required when the codecs are used
    ?mmusrstpprocrun.exe??
    Xmmxp2passion.exemmxp2passion.exeMediaMotor adware
    Xmmxrunmsosa.exeAdded by an unidentified TROJAN or WORM!
    Xmmxrunmswinindex.exeTwoSeven spyware
    Umm_servermm_server.exePart of MusicMatch Jukebox - digital music player / CD burner and ripper / music organizer / playlist creator
    Xmnklinsmnklins.exeVX2.Transponder parasite updater/installer related
    XMNPolmnpol.exeAdded by the DLUCA.B TROJAN!
    UMNSMNS.exeMobile Net Switch enables you to use your computer on more then one network with the click of a button. It allows you to automatically select the correct drive mappings, printer settings, IP settings and much more
    Xmnsamnso.exeAdded by the LINEAG-AI TROJAN!
    Xmnsvcmnsvc.exeAdded by the AUTOUPDER TROJAN!
    Xmnsvcspmnsvcsp.exeAdded by an unidentified VIRUS, WORM or TROJAN!
    ?mnuigomnu.exeWanadoo broadband ISP (now rebranded as Orange) related. What does it do and is it required?
    UMobile Phone SuiteMobilePhoneSuite.exeLogitech Mobile Phone Suite
    Umobile PhoneToolsmPhonetools.exeMotorola Phone Tools
    UMobipocket Reader Notificationsreadernotify.exePart of Mobipocket Reader - "Store all your eBooks, eNews & self-published eDocs on your PC. Download eBooks in Mobi format from your favorite ebookstores to read on your smartphone, PDA, laptop or on your desktop PC"
    UMobipocket Web Companionwebcomp.exeRelated to Mobipocket eBook Reader
    Nmobsyncmobsync.exeMS Syncrhonization Manager - updates the network copy of materials that were edited offline, such as documents, calendars, and e-mail messages
    XMOBSYNC32.EXEmobsync32.exeAdded by the FINERO TROJAN!
    NMODmuamgr.exeUsing MicroAngelo On Display, you can easily select the icon images that you prefer rather than the default icons displayed by Windows. On Display provides a consistent and elegant method to customize the icon display for almost every icon on your system
    XModemlocatesvc.exeAdded by a variant of the SPYBOT WORM!
    XModem Driverz Updatesmdmdrv.exeAdded by a variant of the SDBOT WORM!
    UMODEMBTRMODEMBTR.EXEModem Booster from inKline Global to improve ISP connections
    XModeminfModeminf.exeAdded by a variant of the CRYPTER.C TROJAN!
    UModemOnHoldMOH.EXENetWaiting Modem-on-Hold Application
    NModemUtilitymdmsetpe.exeSystem Tray configuration icon for Aztech modems
    UModPS2ModPS2Key.exeHotkey drivers for Chicony keyboard. Required if you use the hotkeys
    XModularConfigsyscnfg.exeAdded by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside
    XModule Call initializeRUNDLL32.EXE reg.dll, ondll_regAdded by a variant of the LOVGATE WORM!
    XModulo 00FE0F01 Host Internetsyschost.exeAdded by the DELF-KW TROJAN!
    XMonAppliisys32.exeAdded by the ADCLICKER.AE TROJAN!
    NMoney Expressmoneyexpress.exePart of MS Money. Available via Start -> Programs
    NMoneyAgentmoney express.exePart of MS Money. Available via Start -> Programs
    NMoneyAgentmnyexpr.exeMicrosoft Money
    NMoneyStartUpMoney Startup.exeMicrosoft Money
    NMoneyStartUp10.0Activation.exePart of MS Money 2002. Available via Start -> Programs
    Xmonitormonitor.exeBrowser hijacker, redirecting to NCM Search
    UMonitorSD Monitor.exe"Transfer data quickly between your memory card and your computer with SanDisk's Readers, Writers and Adapters"
    UMonitor Apache ServersApacheMonitor.exePart of the Apache Web Server package. Useful only if you're running such a server on your PC. Available via Start -> Programs
    UMonitor Helpermonitor.exeMyLittleSpy keystroke logger/monitoring program - remove unless you installed it yourself!
    XMonitoring Servicesvchost.exeAdded by the CONE.C WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "tasks" subfolder of the Winnt or Windows folder
    XMonitormgtMonitormgt.exeAdded by the GEMA TROJAN!
    UMonitorSDSDMonitor.exeSpyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here
    XMONPluginSrIvcsn3monap23.exeAdded by a variant of the RBOT WORM!
    NMonstersoundtrayFreectrl.exeDiamond Multimedia sound card control panel
    XMonTestvccxzq.exeAdded by the SDBOT-EA WORM!
    UMoodBookmb.exeMoodBook is a free Windows utility that brings art to your desktop
    Nmoon phasemoon.exeMoon Phase - tray icon that indicates the phases of the moon
    XMoreContentrundll32.exe MSA64CHK.dll, DllMostrarMatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder
    XMoreResultsMoreResults.exeMoreResults adware
    NMorpheusmorpheus.exeMusicCity Networks' Morpheus - another peer-to-peer client based on Kazaa. Notable in that this one doesn't seem to install the adware that clog the Kazaa download. They claim they are adware free, and a visitor quotes "I have seen no instance of any since using it"
    Xmorphstbmorphstb.exeAdware - detected by Kaspersky as the STUBBY.C TROJAN!
    Xmosearchmosearch.exeFast Search in Office XP - similar to the new revision of the Find Fast feature in Office 2000. Fast Search uses the Indexing Services in Office XP to create a catalog of Office files on your computer's hard disk. As with Find Fast - a waste of resources. If it can't be disabled via MSCONFIG try here
    XMotherboard ConfigAti2xxx.exeAdded by the RBOT-AIK WORM!
    XMotherBoard SoundsSounds.exeAdded by the RBOT-AAP WORM!
    NMotive SmartBridgempbtn.exeSystem tray icon for the Virtual Assistant from AT&T Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required
    NMotive SmartBridgeMotiveSB.exeSystem tray icon for the Virtual Assistant from AT&T Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required
    NMotive SmartBridgeBTHelpNotifier.exeSystem tray icon for help from BT Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required
    UMotiveMonitormotmon.exeFound on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used?the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufcaturer. For most users it's not required
    NMotiveSBMotiveSB.exeSystem tray icon for the Virtual Assistant from AT&T Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required
    UMotMonmotmon.exeFound on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used?the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufcaturer. For most users it's not required
    Xmotoinmm15201518.Stub.exeDelfin Promulgate adware variant
    UMotorola Desktop SuiteDesktopSuite.exeRelated to Motorola Desktop Suite - PC software managing Motorola mobiles such as the A1000
    UMotorola Desktop Suite mRouter ConfigmRouterConfig.exeConfiguration for Intuwave's mRouter - "that enables easy connectivity between mobile devices and PCs across Bluetooth, Infrared, USB and serial cable connections". An integral component of Symbian OS that is provided to all Symbian licensees
    UMotor_Tracking_ToolMTTool.exeSweex Motion Tracking Webcam utlity. "The motion tracking function ensures that the camera can follow all your movements. So you can move and chat, without disappearing from view"
    UMount Safe & SoundFbmount.exeFrom McAfee VirusScan version 5.x. Creates back-up sets of critical files in a separate area of a hard drive. If you make regular back-ups it's not needed and can be painful during system start
    Umount.exemount.exePart of "GiPo@FileUtilities - GiPo@Mount "Provides advanced substitutional and mounting services. It allows to attach a local drive to an empty folder on an NTFS volume (only for Windows 2000/XP) and to substitute a local folder for a drive letter"
    Xmousemouse.exeAdded by the RBOT-AHJ WORM!
    UMouse 32AMouse32A.exeMouse utility. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
    NMouse Suite 98 Daemonpelmiced.exeMouse driver. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games
    UMouse Suite 98 DaemonICO.EXEFound on some Sony Vaio, IBM Thinkpad and Dell (and possibly other) laptops and seems to be related to Mouse Suite 98 Daemon according to the properties. Required on the Dell Inspirion 530 as without it the Dell mouse suite does not load and mouse settings are not retained on a reboot. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games
    Xmousebutmousebut.exeAdded by the CRYPTER.A TROJAN!
    XMousecntlmousecntl.exeAdded by a variant of the CRYPTER.C TROJAN!
    NMouseCountMC.exeMouseCount by Kittyfeet Software. "Utility for counting how many times us computer junkies click our mouse in a given session/day/week/month/year." Not required
    XMouseDrv[path to worm]Added by the ZOLOAD-B WORM!
    XMouseDrvupdate.exeAdded by the ZOTOB.N WORM!
    UmouseElfMC.exeGenius NetScroll mouse driver - required if you use non-standard Windows driver features
    UmouseElfmouseElf.exeSystem Tray access to the mouse control panel for Genius Netscroll mice. Required if you use non-standard Windows driver features
    UMouseImpMImpHost.exeMouseImp Pro - "A reliable assistant that turns your mouse into a simple, native but powerful controlling device"
    Xmousepadmousepad.exeAdded by the CLICKER TROJAN!
    UMousinfomousinfo.exeMS mouse information tool - for troubleshooting mouse problems
    XMoussaEvil[path to file]Added by the MUSANUB-A WORM!
    XMoveSearchSearch.exePigSearch adware
    NMovielink Manager Uninstallmsvcmm32.exeAuto-update for Movielink - internet movie rental System Tray access
    XMovieMlmovie.exeAdded by the BEAGLE.DS WORM!
    Xmoviemkmoviemk.exeAdded by the DWNLDR-GTB TROJAN!
    XMovieNetworksMovieNetworks.exeMovieNetworks will connect you by DOMESTIC PREMIUM RATE TELEPHONE NUMBER 900-xxx-xxxx. So you get xxx rated pictures and junk. And it will allow you to stay on the internet on their line and $$$ and remove the C:Program FilesMovieNetworks directory
    XMovieplaceMovieplace.exeMoviePlace malware
    XMozilamozila.exeAdded by the DELBOT-AJ WORM!
    XMozila Firefoxfirebox.exeAdded by the RBOT-AIP WORM!
    XMozilla Firebird v0.8 Internet Browsernetstats.exeAdded by the IRCBOT.MC TROJAN!
    XMozilla FirefoxF1REF0X.EXEAdded by a variant of the SDBOT WORM!
    NMozilla Quick LaunchNetscp6.exeNetscape 6 and Mozilla browsers
    NMozilla Quick LaunchMozilla.exeNetscape 6 and Mozilla browsers
    Nmozilla_cleanupxpicleanup.exeFirefox Mozilla cleans up after installation. It is invoked on a restart after installation, to remove the bits and pieces resulting from the installation
    UMozy Statusmozystat.exeMozy - free backup at a secure, remote location
    XMP Tcloakssmptclock.exeAdded by the NACKBOT-B WORM!
    XMP Tcloaxsmptcloaxs.exeAdded by the RANDEX.CT WORM!
    XMP Tclockvvmptclock.exeAdded by the NACKBOT-A WORM!
    XMP Tclockvvmptclockvv.exeAdded by the RANDEX.CJ WORM!
    NMP3 CD ExtractorCD-Extractor.exe"MP3 CD Extractor is an audio CD to MP3 ripper which can extract Digital Audio tracks from Audio CDs into files on the hard disk"
    XMp3 LoaderSysdata.EXEAdded by the AVETTE-A VIRUS!
    XMP3Collectionrundll32.exe MSA64CHK.dll, DllMostrarMatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder
    XMP3downloadrundll32.exe MSA64CHK.dll, DllMostrarMatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder
    XMP3freeDownloadrundll32.exe MSA64CHK.dll, DllMostrarMatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder
    XMP4 Playermp4Player.exeMP4 Player allows you to view MP4 videos. Marked as undesirable due to the fact that it changes your homepage to a custom Google search engine, changes your browser's default search provider, and runs hidden in the background. Terms of use also state that it collects and tracks urls you visit in order to display relevant ads
    UMPEOCsinsm32.exeAutomatic logging of installs from Norton CleanSweep - available via Start -> Programs
    YMPFExempf.exeMcAfee Personal Firewall
    YMPFExeMpfTray.exeMcAfee Personal Firewall
    YMPFTrayMpfTray.exeMcAfee Personal Firewall
    XMPL32 driverMPL32.exeAdded by the LOONY-M TROJAN!
    XMPlay64mplay64.exeAdded by the MPLAY64 TROJAN!
    UMplSetupMplSetup.exeUsed by Ricoh network printers to enable network printing from the client
    XMPM ManagerMPM.exeAdded by the DONBOMB.A TROJAN!
    XMPNetmpn.exeAdded by the DELBOT-W WORM!
    UMPowerMPower.exeMPower from MindBeat. "Defragments and frees your RAM giving more stability to your system and avoiding needless use of swap file. Willl also benchmark (speed test) your hard disk drives and your CPU load". MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
    Xmppddsmppdds.exeAdded by the PWS-AKZ TROJAN!
    Xmppdsmppds.exeAdded by the LEGMIR.AQZ TROJAN!
    XMPR MSGmprmsg32.exeAdded by the MYTOB.CF WORM!
    XMPREXEMPREXE.EXEAdded by the OPASERV.T WORM! Note - this is not the legitimate Mprexe.exe system file
    YMPREXE.exemprexe.exeWIN32 Network Service Interface Process. MPREXE.exe enables the computer to have multiple clients/protocols for networks. There are some problems with it sometimes though - see here. Note - why some people have it listed in start-up programs I don't know but I was asked to include it here. It automatically runs in the background. NOTE : sometimes it will appear in start-ups if you have a virus
    XMprHTMLMprHTML.exeAdded by a variant of the VAGRNOCKER TROJAN!
    Xmprocessormprocessor.exeInstallDollars.com foistware
    UMPSExemscifapp.exeMcAfee.com Privacy Service - "combines personal identifiable information (PII) protection with online advertisement blocking and content filtering"
    YMpsOnnMpsOnn.exeCanon printer driver
    ?MPTMPT.exe??
    XMPtask Servicesmptask.exeAdded by the LALA or AOT TROJANS!
    NMPTBoxMPTBOX.EXECannon Multi-Pass toolbox - a button bar
    Xmptsgsvc.exemptsgsvc.exeHacker Tool - detected by DiamondCS TDS-3 anti-trojan as "HackTool.Win32.Hidd.j"
    NMPXTraympxptray.exeWindows Media Player PowerToy which is run from the taskbar. It can be used to hide Windows Media Player (when in use) and choose various standard buttons (play/pause, next,previous) etc
    UMP_STATUS_MONITORmonitr32.exeCannon Multi-Pass status monitor - your choice
    Xmqbkupmqbkup.exeAdded by the OPASERV.K WORM!
    Xmrsvctrmrsvctr.exeAdded by a variant of the SDBOT WORM!
    YMRTMRT.exeMicrosoft's Malicious Software Removal Tool
    NmrtMngrmrtMngr.exeMaintenance Release Task Manager for Intuit's QuickBooks or Quicken
    UMRU-Blaster Schedulerscheduler.exeScheduler for MRU-Blaster - "a program made to do one large task - detect and clean MRU (most recently used) lists on your computer"
    NMRU-Blaster Silent Cleanmrublaster.exeMRU-Blaster - performs silent cleaning of MRU lists at boot
    UMRUBlasterindexcleaner.exeMRU-Blaster related - runs once in order to delete the index.dat file in the Temporary Internet Files and/or Cookies folder
    XMr_CoolFace_GameEmma.exeAdded by the ROMARIO-A WORM!
    Xmssvhost32.exeAdded by the LEGMIR-AQO TROJAN!
    XMS Auto-IPSec ProtectionMSASP32.exeAdded by the RBOT-AER WORM!
    XMS Autoloader 32MSAuto32.exeAdded by the SPYBOT.BD WORM!
    XMs BuildersWupated.exeAdded by the AGOBOT-SS WORM!
    XMS Configmsdconfig.exeAdded by the RBOT-CZH WORM!
    XMS Config Loadersvchos1.exeAdded by the AGOBOT.R WORM!
    XMS Config LoaderMSWin32bck.exeAdded by the GAOBOT.AA WORM!
    XMS Config Loadersvcrhost.exeAdded by a variant of the RBOT WORM!
    XMS Config ServiceMsloader32.exeAdded by the RBOT-KJ WORM!
    XMS Config v12mscfg12.exeAdded by the AGOBOT.YP WORM!
    UMS Config v13lrbz32.exeAdded by the GAOBOT.AOL WORM!
    XMS Config v13mscfg13.exeAdded by the AGOBOT.YQ WORM!
    XMs configsumsconfigsu.exeAdded by a variant of the SDBOT WORM!
    XMS ConfigurationMSFramer.exeAdded by the RANDEX.OL WORM!
    XMs Configurationmicrosoftsa32.exeAdded by the KELVIR.X WORM!
    XMS DATABASEMSDATA32.EXEAdded by a variant of the SDBOT WORM!
    XMS Decryption Softwareactive.exeMediaTickets adware variant
    XMS DirectX Sound Driversmsdrvdx.exeAdded by the RBOT.BCX WORM!
    XMS DLL Library Managerdllsys64.exeAdded by the RANKY TROJAN!
    XMS Domain Name Server DeamonMSDNSD32.exeAdded by the RBOT-CMZ WORM!
    XMS Domain Name SystemMSWDNS32.exeAdded by the RBOT-GKY WORM!
    XMS DVD DirectX Dll Driversmdxdl.exeAdded by the SDBOT-XI WORM!
    XMS DVD DirectX Sound Driversmsdrvdx.exeAdded by the SDBOT-XJ WORM!
    XMS Explorermexplore.exeAdded by the YAHA.AE WORM!
    XMS FIREWALLmsfrewall.exeAdded by the SDBOT-PU WORM!
    XMS FIREWALLmsfirewall.exeAdded by the SDBOT-QH WORM!
    XMS Hostmsthost.exeAdded by the CHECKOUT WORM! See here
    XMS Host Managerivhost.exeAdded by the RBOT-BJN WORM!
    XMS Hostsmsthosts.exeAdded by a variant of the IRCBOT TROJAN! See here
    XMS HTMLmsHtml.exeAdded by the PESTDOOR.31 TROJAN!
    XMS HTMLmslat.exeAdded by the LATINUS.SVR TROJAN!
    XMS HTML Location ClassMSHTML32.exeAdded by the RBOT-YD WORM!
    XMS Internet Executor 32MSIXEC32.exeAdded by the RBOT-AEQ WORM!
    XMS Internet ExploreMSIEx.exeAdded by a variant of the RBOT WORM!
    XMS Java Applets for Windows NT & XPjavaapplet.exeAdded by the RBOT.BHG WORM!
    UMS Java Applets for Windows NT, ME & XPjavaapplets.exeAdded by the VANEBOT-B WORM!
    XMs Java for Windows 98, NT, ME & XPmsjavames.exeAdded by the RBOT.BHJ WORM!
    XMs Java for Windows 98, NT, XP & MEmsjavaxps.exeAdded by the BACKDOOR.GEN TROJAN!
    XMs Java for Windows NTMS32.exeAdded by the VANEBOT-H WORM!
    XMs Java for Windows NTmsi32java.exeAdded by the VANEBOT-I WORM!
    XMs Java for Windows NTmsjava.exeAdded by the VANEBOT-E WORM!
    XMs Java for Windows NTmsi32info.exeAdded by the RBOT.AFX WORM!
    XMS Java for Windows NT, XP & MExpjavams.exeAdded by the KASSBOT-V WORM!
    XMS Java for Windows XP & NTjavanet.exeAdded by the VANEBOT-A WORM!
    UMS Java Service Wrapper for Windows NT & XPwrapper.exeAdded by the VANEBOT-D WORM!
    XMs Java Update For Windows NT/XPmsijavaupdt32.exeAdded by the RANDEX.AF WORM!
    XMS LARISSAMS_LARISSA.exeAdded by the ASSIRAL.B WORM!
    XMS lsass Startuplsass135.exeAdded by the RBOT.WM WORM!
    ?MS management consolemms.exeSuspicious as the legitimate "Microsoft Management Console" is "mmc.exe" and not "mms.exe" and doesn't normally run at startup
    XMS Microsoft Socket DeamonMSSCKD32.exeAdded by a variant of the RBOT WORM!
    XMS MSN Menssenger 7.0MSMSN7.exeAdded by the RBOT-ACA WORM!
    XMS MSN Menssenger 7.0MSEXPORT.exeAdded by a variant of the SDBOT WORM!
    XMS Network Controlmswin.exeAdded by the DUMBA TROJAN!
    Xms ownagewinPE.exeAdded by the RBOT-AJL WORM!
    XMS PLUS INCwpad.exeAdded by the MYTOB-AN WORM!
    XMs Processe Managermsproc.exeAdded by the RBOT.ATO WORM!
    XMS Real PlayerRealPlyr.exeAdded by the RBOT.MR WORM!
    XMS Registry ServiceMSRMS32.exeAdded by the RBOT-AKP WORM!
    XMS Remote Procedure Callmsrpc32.exeAdded by the RBOT-QL WORM!
    XMS Screen Saverscrsave.scrAdded by the RBOT-AGT WORM!
    XMS Securitysystm.pifAdded by the RBOT-AQN WORM!
    XMS Security Authority Servicelsass.exeAdded by the KALEL-B WORM! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder
    XMS Security Hotfixservice5.exeAdded by the GAOBOT.AG WORM!
    XMS Security Update 993msident.exeAdded by a variant of the SDBOT WORM!
    XMS servicemsservice.exeAdded by the RBOT-ZG WORM!
    XMS Service Driverswinscv.exeAdded by the SDBOT-COG WORM!
    XMs sock for Windows NTwinser.exeAdded by a variant of the SDBOT WORM!
    XMS Sound Config 16bitsndcfg16.exeAdded by the SDBOT.MB TROJAN!
    XMs Sound Driversmsdrv.exeAdded by the SDBOT-WR WORM!
    Xms spool servicemsspooler.exeAdded by a variant of the RBOT WORM!
    XMs Spool32MS SPOOL32.EXEAdded by the ASASSIN TROJAN!
    XMS SyS Restoresysrestore.exeAdded by the RBOT.XM WORM!
    XMS Sys Securitymswin.pifAdded by the RBOT-APJ WORM!
    XMS System Call Functionmsscf32.exeAdded by the RBOT-GBZ WORM!
    XMs System ConfigMscfg.exeAdded by the SDBOT-CCR WORM!
    XMs System Configpcedit.exeAdded by a variant of the SDBOT WORM!
    XMS System Securitymswin32.pifAdded by the RBOT-AOX WORM!
    XMs task managertskmgr.exeAdded by the SDBOT.CCD WORM!
    XMS Task Manager 32mstskmgr.exeAdded by the RANKY.DE TROJAN!
    XMS taskbarcrssr.exeAdded by the RBOT-AGO WORM!
    XMS taskbarnts.exeAdded by the RBOT-AGB WORM!
    XMS taskbartaskbars.exeAdded by the RBOT.BRW WORM!
    XMS Taskbarstaskbars.exeAdded by the SDBOT-ACV WORM!
    XMS taskmanagertskmgr.exeAdded by the RBOT-AKA WORM!
    XMS Timetimezone.exeAdded by the AGOBOT.ADY WORM!
    XMS UniXnavupdate64.exeAdded by a variant of the RBOT WORM!
    XMS Unix Binarywin32ttb.exeAdded by the SPYBOT.OQ WORM!
    XMS Unix Binarymsmq2inst.exeAdded by the RBOT-YF WORM!
    XMS Unix Binarymsnupdate.exeAdded by the RBOT-AAM WORM!
    XMS Unix Binaryoutlookexpressupdate.exeAdded by the RBOT-YU WORM!
    XMS Unix BinaryWin32Update.exeAdded by the RBOT-BAS WORM!
    XMS Unix BinaryNorton2005Update.exeAdded by a variant of the RBOT WORM!
    XMS Unix Binarytrmupdate.exeAdded by the RBOT-ACC WORM!
    XMS Unix BinaryWinGuard.exeAdded by the RBOT-ACL WORM!
    XMS Unix Binarymsnq3insller.exeAdded by a variant of the RBOT WORM!
    XMS Updatesyshost.exeAdded by the EVAMAN-F WORM!
    XMs Update WinServices NT/XPwinservnt32.exeAdded by the VANEBOT-G WORM!
    XMS Updatesmscache.exeSpyware web downloader
    XMS Updatessyshosts.exeAdded by the MYDOOM.Y WORM!
    XMS Updatesaupd.exeSpyware web downloader
    XMS Updating Utilitymsupdater.exeAdded by the RBOT-XR WORM!
    XMS USB 2.0 Windows Supportmsusb32.exeAdded by a variant of the RBOT WORM!
    XMs Valud LoaderSvhots.exeAdded by the AGOBOT-SP WORM!
    XMS Win32 Network Serviceswindriver.exeAdded by the AGOBOT.ADH WORM!
    Xms window update******.exe [* = random character]Added by a variant of the RBOT WORM!
    XMS Windows AOL DriverMSAOLdrv.exeAdded by the RBOT-ASP WORM!
    XMS windows Data list processMSDATLST.exeAdded by an unidentified WORM or TROJAN!
    XMS Windows Executor ProcessMSEXECP32.exeAdded by a variant of the RBOT WORM!
    XMS Windows Local DirectoryMSWLD32.exeAdded by a variant of the RBOT WORM!
    XMS Windows procces 32msprocces.exeAdded by the RBOT-AEZ WORM!
    XMS Windows Process ClassMSPRCSS32.exeAdded by the RBOT-YQ WORM!
    XMS Windows Process InitMSWPI32.exeAdded by the RBOT-ASQ WORM!
    XMS Windows Security Updaterupdater.pifAdded by the RBOT-AKY WORM!
    XMS Windows System AlertMSWSA32.exeAdded by the RBOT-BFN WORM!
    XMS Windows TASK ServiceMSWTASK32.exeAdded by a variant of the RBOT WORM!
    XMS Windows Updatescguard.exeAdded by the RBOT-YZ WORM!
    XMS WINS Binaryign32.pifAdded by the RBOT-ASB WORM!
    Xms************* [* = random digit]ms*************.exe [* = random digit]WINBO adware
    XMs**.exe [* = random char]Ms**.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
    XMs**32.exe [* = random char]Ms**32.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
    XMS-Connectarr.exeAdult content dialler - see here
    XMS-Connectcdm.exeAdult content dialler - see here
    XMS-Connectgame.exeAdult content dialler - see here
    XMS-Connectmsite18.exeAdult content dialler - see here
    XMS-Connectweb.exeAdult content dialler - see here
    XMS-DOS Boot ServiceBoot32.pifAdded by the RBOT-AMF WORM!
    XMS-DOS Security Servicems-dos.pifAdded by the RBOT-AMR WORM!
    XMS-DOS ServiceMS-DOS.pifAdded by the RBOT-AII WORM!
    XMS-DOS Windows ServiceMS-DOS.PIFAdded by the RBOT-AJW WORM!
    XMS-HTML[random filename]Added by the LATINUS.15 TROJAN!
    XMS-patchmsconfig32.exeAdded by the RBOT-AUF WORM!
    XMS-patchmspatch32.exeAdded by the RBOT-AWF TROJAN!
    XMS-RunKeyarr.exeMS-Connect dialler/hijacker
    Xms2srcms2src.exeAdded by a TROJAN - see here
    XMS32DLLachi.dll.vbsAdded by the ACHI-A TROJAN!
    XMS32DLLBha.dll.vbsAdded by the BUTSUR-A WORM!
    XMS32DLLBha.dll.vbsAdded by the BUTSUR-A WORM!
    XMS32DLLMS32DLL.dll.vbsAdded by the ZODGILA WORM!
    XMS7531ms7531.exeHomepage hijacker
    XMSACMmsacm.exeAdded by the OPASERV-O WORM!
    Xmsadcheckmsadcheck32.exeBrowser hijacker, redirecting to search-system.com
    XMSAdminjdbgmrg.exeAdded by the DASMIN.A TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here
    XMSAgentmshtm.exeBrowser hijacker - redirecting to buldog-search.com
    XMSAgenthhnt.exeAdded by the AGENT.JI spyware
    XMSAgentXPMSAgentXP.exeReported by Ewido Security Suite as TrojanDownloader.Reqlook.c
    Umsaimmsaolim.exeMessageSpy keystroke logger/monitoring program - remove unless you installed it yourself!
    Xmsappts32msappts32.exeAdded by the ELBURRO-A TROJAN!
    XMsAudioexplorer.exeAdded by the LEGMIR-BY TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System (9x/Me) or System32 (NT/2K/XP) folder
    XMsAudioMsVM_STI.EXE RunDll32 cmicnfg.cpl, CMICtrlWndAdded by the LEGMIR-BY TROJAN! Note - this is not associated with C-Media based audio which uses a similar command entry (see here)
    XMSbackupsbackups.exeAdded by the BANLOAD-TL TROJAN!
    XMSBBmsbb.exeAdvertising spyware
    Xmsbcsmsbcs.exeAdded by the DADOBRA-G TROJAN!
    XMsBootMgr.exeMsBootMgr.exeAdded by the VERIFY TROJAN!
    Xmsbsc[path to trojan]Added by the BANKER-DF TROJAN!
    Xmsccrtmsccrt.exeAdded by the PWS-ALA TROJAN!
    Xmscheckrundll32.exe wincheck071008.dll mymainDetected by Trend Micro as the AGENT.ADXH TROJAN! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wincheck071008.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    Xmschkdf.exemschkdf.exeAdded by a variant of the SDBOT WORM!
    XMSChoExEsuge.exeAdded by a variant of the RBOT WORM!
    ?mscimcinfo.exeMcAfee Internet Security related. What does it do and is it required?
    Xmscmanmscman.exeClientMan parasite variant
    Umscnmscn.exePart of the SafeChildNet internet filtering program - required if you use it
    XMscntmscnt.exeAdded by the DLUCA-C TROJAN!
    XMscolourmscolour.exeAdded by the GEMA TROJAN!
    XMSCommXmscommx.exeAdded by a variant of the RBOT WORM!
    XMSCONFG32.EXEMSCONFG32.EXEAdded by the OPTIX.04.C TROJAN!
    NMSConfigmsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group, and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode
    XMSConfigMSCONFIG32.EXEAdded by the SPYBOT.B WORM!
    Xmsconfigmsconfig.exeCoolWebSearch parasite related. Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting
    XMsconfigmsconfig.exeAdded by the WINUR WORM! Note - this is not the real msconfig.exe as it's located in C:winrun
    Xmsconfigwins.exeAdded by the RBOT.PF WORM!
    XMSConfigMSCONFIG35.EXEAdded by a variant of the SPYBOT WORM!
    Xmsconfigscvhost.exeAdded by the AGENT-DSF TROJAN!
    Xmsconfigwinlog.exeAdded by the IRCBOT-TJ TROJAN!
    XMsconfigicpldrvx.exeAdded by the BANLOAD.BFT TROJAN!
    Xmsconfigmsconfig.comAdded by the IRCBOT-SM WORM!
    Xmsconfigmsconfig.batAdded by the PAHATIA.B WORM!
    XMsconfig lptt01msconfig.exeRapidBlaster variant (in a "msconfig" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name
    XMSConfig Managermsupdate.exeCoolWebSearch parasite variant
    XMsconfig ml097emsconfig.exeRapidBlaster variant (in a "msconfig" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name
    Xmsconfig serviceMSupdate32.exeAdded by a variant of the SPYBOT WORM!
    Xmsconfig.exeproxy.exeAdded by a variant of the AGENT.AH downloader TROJAN!
    Xmsconfig.exeuline.exeAdded by a variant of the AGENT.AH downloader TROJAN!
    Xmsconfig38mssvcc.exeAdded by the RBOT-BJV WORM!
    XMSConfig45MSConfig45.exeAdded by the SDBOT.OJ TROJAN!
    XMSConfigrjdbgmrg.exeAdded by the DASMIN.C TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here
    NMSConfigRemindermsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group, and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode
    XMsConfigsMsConfigs.exeAdded by the ALCAN.A WORM!
    XMSConfigsRUNDLL64.dll.vbsAdded by the WEKODE-B WORM!
    XMSControl28crsss.exeAdded by the SPYBOT.AJX WORM!
    XMSControl31winnsyst.exeAdded by the RBOT.CFY WORM!
    XMSControl3d1isasse.exeAdded by the RBOT.CGU WORM!
    XMSCOREsyscnfg.exeAdded by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside
    XMscsgsMSCSGS.EXEAdded by the ZEZER WORM!
    XMscsgs32MSCSGS32.EXEAdded by the ZEZER WORM!
    Xmscsvc.exemscsvc.exeAdded by the BANCOS.T TROJAN!
    Xmsctrl.exemsctrl.exeDetected by Kaspersky as the AGENT.ANQ TROJAN! See here
    XMsctrl32Msctrl32.scrAdded by the REDIST WORM!
    XMSCVTMSCVT.exeAdded by the SLIDESHOW WORM!
    Xmsdbgm.exemsdbgm.exeAdded by the CIMUZ-CQ TROJAN!
    XMSDcomMSDcom.exeAdded by a variant of the SDBOT WORM!
    Xmsdefender.exemsdefender.exeDetected by Trend Micro as the PAKES.ZL TROJAN! See here
    Xmsdevmsdev.exeAdded by the FORBOT-CR WORM!
    Xmsdevmsconfig.exeAdded by the AGOBOT.AAU WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting
    Xmsdir32msdir32.batAdded by the ROOKIE-A TROJAN!
    Xmsdirect.exemsdirect.exeAdded by the CERTIF-L TROJAN!
    XMSDLLsyscnfg.exeAdded by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside
    XMsdmxmmsdmxm.exeAdded by the DLOAD-DC TROJAN!
    XMSDNnese.exeAdded by the SDBOT.AHY WORM!
    XMSDN for Windows NTmsdn.exeAdded by a variant of the RBOT WORM!
    XMSDN for Windows NT & WinXPmsdnxp.exeAdded by the IRCBOT-PE WORM!
    XMSDN for Windows with NT'smsdn-nt.exeAdded by the RBOT-EWD WORM!
    XMSDN HELPmsdn.exeAdded by the AGOBOT.AIB WORM!
    XMSDNNhelp.exeAdded by the AGENT-GBK TROJAN!
    XMSDOS Security Servicemsdos.pifAdded by the RBOT-AMP WORM!
    XMSDOS ServiceMSDOS.PIFAdded by the RBOT-AIY WORM!
    XMSDOS Windows ServiceMSDOS.PIFAdded by the RBOT-AKF WORM!
    XMsdos32Msdos32.pifAdded by the RECORY WORM!
    Xmsdos423msdos423.exeAdded by the MENACE.A WORM!
    NMSDosdrvmsdosdrv.exeAdded by the BACROS WORM!
    XMSDriverundll32.exe drvkoc.dllAdded by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "drvkoc.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    XMSDriverundll32.exe drvmod.dllAdded by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "drvmod.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    XMSDriverundll32.exe drvsoh.dllAdded by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "drvsoh.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
    Xmsdrvctrlmsdrvctrl.exeDetected by Kaspersky as the AGENT.BN TROJAN! See here
    NMSDTCmsdtc.exeMS Distributed Transaction Coordinator - handles transactions across multiple servers and is installed by MS Personal Web Server and MS SQL Server
    XMsemu32Msemu32.exeUnidentified spyware/adware/hijacker
    Xmsenngerl4m3r.exeAdded by the PROGENT-AF TROJAN!
    Xmservices.exemservices.exeAdded by the SDBOT.WJ WORM!
    XMsfindMsfind.exeCoolWebSearch parasite variant
    XMSFind32msfind32.exeAdded by the CAYAM WORM!
    Xmsfindosa.exemsfindosa.exeAdded by the DOWNLOADER-BS TROJAN!
    XMSFTP Service Configr3grun.exeAdded by a variant of the SDBOT WORM!
    Xmsfw.exemsfw.exeDetected by Kaspersky as the AGENT.ANQ TROJAN! See here
    XMSFWAVTSMFTPDev.exeAdded by the RBOT-ACF WORM!
    XMsg Fixagemsgfixed.exeAdded by the SDBOT.ZD WORM!
    XMsgApi[path to file]Added by the DEDLER-D TROJAN!
    Xmsgb1msgb1.exeAdded by the DLUCA.GEN TROJAN!
    NMsgCenterExeRealOneMessageCenter.exeRealNetworks RealPlayer related - disabling this application will not affect Real Player in any way
    Xmsgex32msgex32.exeAdded by the APPFLET-A WORM!
    XMsgmgr[path to worm]Added by the BABYBEAR WORM!
    Xmsgserv_Syss.exeAdded by the FANTA TROJAN!
    Xmsgsm32msgsm32.exeAdded by the RBOT-ASG WORM!
    XMsgsrv16Msgsrv16.exeAdded by the DELF family of TROJANS!
    YMSGSRV32.exemsgsrv32.exeWindows 32-bit VxD Message Server. For more information on its function and why it's needed, see here. Note - why some people have it listed in start-up programs I don't know but I was asked to include it here. It automatically runs in the background
    XMsgsvc32[worm filename]Added by the NAUTICAL-A WORM!
    XMsgSvcMgr32cmdzxdll.exeAdded by the RBOT-AEK WORM!
    Xmsgsvr32msgsvr32.exeAdded by the DEADHAT.B WORM! Note - not to be confused with the valid "msgsrv32.exe" file which resides in the same directory (C:WindowsSystem) on a Win9x/Me machine
    UMSGTAGMSGTAG.exeMSGTAG is an application that tells you when your emails have been received and opened
    XMsgtraysys16.exeAdded by an unknown VIRUS!
    XMshelp32mshelp32.exeCoolWebSearch parasite variant
    XMSHT@MSHT@.EXEAdded by the MAGISTR.A VIRUS!
    Xmshtmllmshtmll.dllAdded by the DELF.BAS TROJAN!
    XMSI Configurationmsiconf.exeAdded by the AGENT.AKSZ TROJAN!
    Xmsiconf.exemsiconf.exeAdded by a variant of the FAKEALERT TROJAN!
    Xmsidentmsident.exeUnidentified adware or trojan
    Xmsidlemsidle.exeAdded by the OPASERV-O WORM!
    XMsIdle32.exeMsIdle32.exeAdded by the VERIFY TROJAN!
    XMSIdllwinmp.exeAdded by a variant of the RBOT WORM!
    XMSIE ParsersMSIE32ab.exeAdded by the SDBOT.MV WORM!
    Xmsiemon.exemsiemon.exeDetected by Kaspersky as the AGENT.ANQ TROJAN! See here
    Xmsiewmseiw.exeAdded by the LITTLOG TROJAN!
    XMSIEXECMSIEXEC32.exeAdded by the AINESEY.A WORM!
    XMSIEXECMSIEXEC.EXEAdded by the YOSENIO-A VIRUS!
    Xmsiexecs.exemsiexecs.exeAdded by a variant of the SDBOT WORM!
    Xmsigdisk10.exeAdded by the BANBRA-KF TROJAN!
    XMsIMMs32MsIMMs32.exeONLINEG.GDJ spyware
    Xmsimnmsimn.exeAdded by the AGOBOT.JL WORM!
    XMSIMN32MSIMN32.EXEAdded by the CWS-M TROJAN!
    ?MSINMSin.exe??
    XMsinetMsinet.exeAdded by the RBOT-AOA WORM!
    XMSInfomsinfo.exeAdded by the ALADINZ.M TROJAN!
    XMSInfoAVBgle.exeAdded by the NETSKY.O WORM!
    XMSInstallsmvss.exeAdded by the DEDLER-G TROJAN!
    Xmsjava servicexpcd.exeAdded by the SDBOT.VM WORM!
    UMSKAGENTEXEMskAgent.exe